CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,532
- of 17,787 indexed, latest versions
- Container images
- 1,541
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,532 of 17,787 indexed charts deploy, on 1,541 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 892 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 426 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 310 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,532 by stars
Container images carrying it
1,541 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bbernhard/ | 549ad08d7e14 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| beanbag/ | 6b840f546e1c | openssl | no fix listed | 1 |
| behnambm/ | bd3ad88afff9 | cryptography | 42.0.2 | 1 |
| belirta/ | f65ad0e23b4d | openssl | 3.0.12-r4 | 1 |
| benbusby/ | f77f7e6e4ad2 | cryptography | 42.0.2 | 1 |
| beopenit/ | d24c323fe7c3 | openssl | 3.1.4-r5 | 1 |
| bicarus/ | b1dab0721e1c | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| binwiederhier/ | 83e2e43d9956 | openssl | 3.1.4-r5 | 1 |
| bitnamilegacy/ | 15d4647fd491 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | cc599cbd15ff | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | f5fc0d561d9e | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 1d80b6a96f00 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 3163c3842bfd | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 6e412c178ef9 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | d24925821dd2 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 3332e81afb4f | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 90fda44bfa42 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | cc55da2fa366 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | ea55532b6f75 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | fdc6979dbc53 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 5261cae9e407 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 70cafc5a71e8 | openssl | 3.0.13-1~deb12u1 | 1 |
| bitnamilegacy/ | 9c6fecd24bf3 | openssl | 3.0.13-1~deb12u1 | 1 |
| blakeblackshear/ | ae269270ad9e | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| bnjbvr/ | 37e216b182c8 | cryptography | 42.0.2 | 1 |
| bnwokoye/ | 74de7dc7ebfb | openssl | 3.0.12-r4 | 1 |
| boxcutter/ | 84e13f01bcab | openssl | 3.0.2-0ubuntu1.14 | 1 |
| browserless/ | c81ae5585b47 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| btungut/ | 4a072e2edf71 | openssl | 3.1.4-r5 | 1 |
| camerahub/ | a5af37dd6e1b | cryptography | 42.0.2 | 1 |
| camptocamp/ | 35c91d5fda04 | cryptography | 42.0.2 | 1 |
| camptocamp/ | bff736b15623 | cryptography | 42.0.2 | 1 |
| camptocamp/ | 2924b43dbf40 | cryptography | 42.0.2 | 1 |
| camunda/ | ab5abc09e407 | openssl | no fix listed | 1 |
| casbin/ | 66f836ef778b | openssl | 3.0.12-r4 | 1 |
| catalysm/ | f003b35f54d9 | openssl | 3.1.4-r5 | 1 |
| cdignam/ | 5a6a55b39cee | cryptography | 42.0.2 | 1 |
| ceph/ | 90f30824a96e | cryptography | 42.0.2 | 1 |
| ceticasbl/ | 6c0aa7567145 | cryptography | 42.0.2 | 1 |
| cfcontainerization/ | 82fa261c18a8 | openssl-1_1 | 1.1.1w-7.1 | 1 |
| cfcontainerization/ | 58fb1c173a46 | openssl-1_1 | 1.1.1w-7.1 | 1 |
| chandanteekinavar/ | c96f759b6ce4 | openssl | 3.1.4-r5 | 1 |
| checkmk/ | c11b422210c4 | openssl | no fix listed | 1 |
| chetangautamm/ | b4b94155ff5a | openssl | 1.0.1f-1ubuntu2.27+esm10 | 1 |
| chetangautamm/ | e7f7049e1544 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| cheveo/ | 82240f890884 | openssl | no fix listed | 1 |
| cheyang/ | 46cc34755493 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| chirpstack/ | fb7667fe037f | openssl | 3.0.12-r4 | 1 |
| chirpstack/ | c0bbbb7a3f1e | openssl | 3.0.12-r4 | 1 |
| chorss/ | 5c549cacb8ab | cryptography | 42.0.2 | 1 |