CVE-2024-0727
MediumAdvisory
Published 26 Jan 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,532
- of 17,787 indexed, latest versions
- Container images
- 1,541
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Null pointer dereference in PKCS12 parsing
Carried by container images the latest versions of 1,532 of 17,787 indexed charts deploy, on 1,541 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+75 more | 1.0.1f-1ubuntu2.27+esm10, 1.0.2g-1ubuntu4.20+esm11, 1.1.1-1ubuntu2.1~18.04.23+esm4, 1.1.1f-1ubuntu2.21+4 more | 892 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+17 more | 3.0.12-r4, 3.1.4-r5, 3.2.1-r0 | 426 |
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+44 more | 42.0.2 | 310 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm1 | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| openssl-1_1rpm | 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.1 | 1.1.1d-150200.11.85.1, 1.1.1w-7.1 | 3 |
- OSV records
- ALPINE-CVE-2024-0727CGA-695v-9975-r7j4DEBIAN-CVE-2024-0727GHSA-9v9h-cgj8-h64pUBUNTU-CVE-2024-0727openSUSE-SU-2024:13662-1SUSE-SU-2024:0832-1
- Also known as
- CGA-h3v7-jg5r-3grr, PYSEC-2026-1285, USN-6622-1, USN-6632-1, USN-6709-1, USN-7018-1
Charts affected
1,532 by stars
Container images carrying it
1,541 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| dellcloud/ | 6ba7b22caacd | openssl | 1.1.1f-1ubuntu2.21 | 79 |
| flyway/ | 22d97ceb0c47 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 79 |
| library/ | 4bc6bc963e6d | cryptography | 42.0.2 | 22 |
| codeurjc/ | 9fb4c11e6a49 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 13 |
| oomk8s/ | 875814cc853d | cryptography openssl | 42.0.2 1.0.2g-1ubuntu4.20+esm11 | 11 |
| library/ | 8e70544b6c76 | openssl | 1.1.1f-1ubuntu2.21 | 10 |
| library/ | 8a279e9396a8 | openssl | no fix listed | 10 |
| curlimages/ | 08e466006f08 | openssl | 3.1.4-r5 | 7 |
| library/ | a42d2b4503e7 | openssl | no fix listed | 7 |
| library/ | ce66c7be32a0 | openssl | no fix listed | 6 |
| library/ | dbaa3e69f563 | openssl | 3.1.4-r5 | 6 |
| oomk8s/ | 7daa08b81954 | openssl | 1.0.2g-1ubuntu4.20+esm11 | 6 |
| quay.io/ | 95d6f0e05636 | openssl | 3.0.13-1~deb12u1 | 6 |
| quay.io/ | fbeaef7a8566 | openssl | 3.1.4-r5 | 6 |
| quay.io/ | 1b594392f7cb | openssl | 3.0.13-1~deb12u1 | 6 |
| bitnamilegacy/ | c74b703deed2 | openssl | 3.0.13-1~deb12u1 | 5 |
| library/ | 4be76f674fc4 | openssl | 1.1.1f-1ubuntu2.fips.20 | 5 |
| natsio/ | a67913df95f1 | openssl | 3.1.4-r5 | 5 |
| solsson/ | 41e5d8f6f290 | openssl | 1.1.1f-1ubuntu2.21 | 5 |
| hyperledger/ | a70b6ba64a08 | openssl | no fix listed | 4 |
| hyperledger/ | 4ce6f43ded2e | openssl | 1.0.2g-1ubuntu4.20+esm11 | 4 |
| hyperledger/ | f6c724592abf | openssl | 1.0.2g-1ubuntu4.20+esm11 | 4 |
| jaegertracing/ | d48d6dab2c65 | openssl | 3.0.2-0ubuntu1.14 | 4 |
| library/ | 5e15a3f014ed | openssl | 1.1.1f-1ubuntu2.fips.20 | 4 |
| library/ | 628741415fc9 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 4 |
| library/ | 6efa05203990 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 4 |
| library/ | c3f70098e01d | openssl | no fix listed | 4 |
| mastercloudapps/ | 40a950b311b2 | openssl | 3.0.2-0ubuntu1.14 | 4 |
| oscarsotosanchez/ | 911ec961d10b | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm4 | 4 |
| ghcr.io/ | 0c00cb0bda1a | openssl | no fix listed | 4 |
| ghcr.io/ | ab2e1fa19dd4 | openssl | 3.1.4-r5 | 4 |
| ghcr.io/ | 60c1562e4d51 | openssl | 3.1.4-r5 | 4 |
| alfhou/ | c85dc0293aa1 | openssl | 3.1.4-r5 | 3 |
| argoproj/ | 830e86cacefd | cryptography | 42.0.2 | 3 |
| caddy/ | 18d1366fc0e9 | openssl | 3.1.4-r5 | 3 |
| ciscolabs/ | a7b60ec88285 | openssl | 1.1.1f-1ubuntu2.21 | 3 |
| ciscolabs/ | b59fc10bb821 | openssl | 1.1.1f-1ubuntu2.21 | 3 |
| cloudve/ | 4a3d7fae90bb | cryptography openssl | 42.0.2 1.1.1f-1ubuntu2.21 | 3 |
| codeurjc/ | 800cf520c245 | openssl | 3.0.2-0ubuntu1.14 | 3 |
| dgraph/ | 3b55ea83fffe | openssl | 1.1.1f-1ubuntu2.21 | 3 |
| dpage/ | 781369df9994 | cryptography | 42.0.2 | 3 |
| envoyproxy/ | 2bf7f042e396 | openssl | no fix listed | 3 |
| jacobalberty/ | 896c0ab82d33 | openssl | 1.1.1f-1ubuntu2.fips.20 | 3 |
| library/ | af96c680a7e1 | openssl | 3.1.4-r5 | 3 |
| library/ | a484819eb602 | openssl | 3.0.13-1~deb12u1 | 3 |
| mysql/ | d6c8301b7834 | cryptography | 42.0.2 | 3 |
| natsio/ | b3359eeb10bf | openssl | 3.1.4-r5 | 3 |
| omecproject/ | d59ccb138ffb | openssl | 1.0.2g-1ubuntu4.20+esm11 | 3 |
| pnnlmiscscripts/ | 9a2fe06a1472 | openssl | 3.0.12-r4 | 3 |
| rcdelacruz/ | 38007f358355 | openssl | 3.1.4-r5 | 3 |