CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,532
- of 17,787 indexed, latest versions
- Container images
- 1,541
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,532 of 17,787 indexed charts deploy, on 1,541 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 892 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 426 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 310 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,532 by stars
Container images carrying it
1,541 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| chriseaton/ | 54c3384ce701 | openssl | no fix listed | 1 |
| chrisfu/ | f8b4996a203d | openssl | 3.1.4-r5 | 1 |
| chrislusf/ | ed80f00fde46 | openssl | 3.1.4-r5 | 1 |
| chriswells0/ | f3918ec8471c | openssl | 3.1.4-r5 | 1 |
| circleci/ | 4d8d0ae5efc3 | openssl | 3.0.12-r4 | 1 |
| circleci/ | 9bdc62f02162 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| ciscolabs/ | 36d02faad958 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| citizenstig/ | b81c818ccb86 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| ckan/ | ef8e5d3e6be1 | openssl | no fix listed | 1 |
| clickhouse/ | 01b81d1432c4 | openssl | no fix listed | 1 |
| clickhouse/ | 1ffa82edee00 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| clickhouse/ | 2e6587b81a26 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| clickhouse/ | 512bb8a21483 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| clickhouse/ | 810861a2e2d0 | openssl | no fix listed | 1 |
| clickhouse/ | 8745843b17f9 | openssl | no fix listed | 1 |
| clickhouse/ | 92098d3b31dd | openssl | no fix listed | 1 |
| clickhouse/ | a65ca89ddbe8 | openssl | no fix listed | 1 |
| clickhouse/ | b627d7a9bc0e | openssl | no fix listed | 1 |
| clickhouse/ | dc5658853ce1 | openssl | 3.0.2-0ubuntu1.14 | 1 |
| clickhouse/ | e019438e1e05 | openssl | no fix listed | 1 |
| cloudnativelabs/ | 0ec7cd73f43f | openssl | 3.0.12-r4 | 1 |
| cloudve/ | af56e77ca587 | cryptography openssl | 42.0.2 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| cloudve/ | d79c1c5881c0 | cryptography openssl | 42.0.2 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| codecov/ | 0475cb1c3136 | cryptography openssl | 42.0.2 3.1.4-r5 | 1 |
| coldatom/ | eae9e82da080 | openssl | 3.0.12-r4 | 1 |
| coldatom/ | 7c2fbbb41bcf | openssl | 3.0.12-r4 | 1 |
| collabora/ | 05299b452f7f | openssl | 3.0.13-1~deb12u1 | 1 |
| confluentinc/ | f2975d507a2a | cryptography | 42.0.2 | 1 |
| confluentinc/ | 8f1544df1f48 | cryptography | 42.0.2 | 1 |
| confluentinc/ | 3bf359d5e340 | cryptography | 42.0.2 | 1 |
| confluentinc/ | c0224a1adf7a | cryptography | 42.0.2 | 1 |
| confluentinc/ | dc9b972db002 | cryptography | 42.0.2 | 1 |
| confluentinc/ | 4bc70a83ca6f | cryptography | 42.0.2 | 1 |
| confluentinc/ | b0b7aa26254a | cryptography | 42.0.2 | 1 |
| confluentinc/ | 8ec46c27982f | cryptography | 42.0.2 | 1 |
| confluentinc/ | ee403d5b9090 | cryptography | 42.0.2 | 1 |
| confluentinc/ | b651d4b6185a | cryptography | 42.0.2 | 1 |
| confluentinc/ | 0bec03c1f3ce | cryptography | 42.0.2 | 1 |
| confluentinc/ | 78c190f4472c | cryptography | 42.0.2 | 1 |
| cortezaproject/ | 0bcdcbcd3c63 | openssl | no fix listed | 1 |
| cortezaproject/ | 8eb7a26605c9 | openssl | 1.1.1f-1ubuntu2.fips.20 | 1 |
| cortezaproject/ | cb9f200de5d2 | openssl | no fix listed | 1 |
| countly/ | e3c238248f99 | openssl | 1.1.1f-1ubuntu2.21 | 1 |
| cradlepoint/ | 8f5720b0cd03 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 1 |
| crazymax/ | 841b10cdae76 | openssl | 3.1.4-r5 | 1 |
| crazymax/ | fb307f5b87bf | openssl | 3.0.12-r4 | 1 |
| cribl/ | 762747cb6796 | openssl openssl1.0 | 1.1.1-1ubuntu2.1~18.04.23+esm4 1.0.2n-1ubuntu5.13+esm1 | 1 |
| csiplugin/ | 1fa83d45417f | openssl | 1.0.2g-1ubuntu4.20+esm11 | 1 |
| curlimages/ | 5af13420d29b | openssl | 3.0.12-r4 | 1 |
| cyverse/ | aa69d105b292 | openssl | no fix listed | 1 |