StackRadar

CVE-2024-0985

High

Advisory

Published 8 Feb 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
222
of 17,781 indexed, latest versions
Container images
223
deployed by those charts
Fix available
12 of 14
affected packages

PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL

Carried by container images the latest versions of 222 of 17,781 indexed charts deploy, on 223 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u115.6-0+deb12u128
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+1 more12.18-0ubuntu0.20.04.116
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+2 more14.11-0ubuntu0.22.04.19
postgresql15apk15.1-r0, 15.2-r0, 15.3-r0, 15.4-r0+1 more15.6-r09
postgresqlbitnami14.4.0-0, 14.4.0-11, 15.2.0-4, 15.3.0-3+3 more12.18.07
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql14apk14.4-r0, 14.5-r0, 14.10-r014.11-r06
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-4212.18.04
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.049.5.25-0ubuntu0.16.04.1+esm73
postgresqlrpm13.23-1.el9_70:15.6-1.module+el9.3.0+21283+b0ea34b61
postgresql16apk16.1-r016.2-r01
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-13deb13.3-1, 13.4-0+deb11u1, 13.5-0+deb11u1, 13.6-1.pgdg110+1+8 more13.14-0+deb11u176
postgresql-11deb11.4-1, 11.5-1+deb10u1, 11.7-0+deb10u1, 11.9-0+deb10u1+11 more11.22-0+deb10u260
OSV records
ALPINE-CVE-2024-0985BIT-postgresql-2024-0985DEBIAN-CVE-2024-0985RHSA-2024:0950UBUNTU-CVE-2024-0985DLA-3764-1DSA-5622-1
Also known as
DSA-5623-1, USN-6656-1, USN-6656-2

Charts affected

222 by stars
ChartLatestAffected imagesRadar Score
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.22-0+deb10u2

Open the chart page →

3,313
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
postgresql-13@13.7-1.pgdg110+1
13.14-0+deb11u1

Open the chart page →

2,637
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
12.18.0

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
postgresql-11@11.7-0+deb10u1
11.22-0+deb10u2

Open the chart page →

8,694
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
postgresql-13@13.10-0+deb11u1
13.14-0+deb11u1

Open the chart page →

7,574
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1

Open the chart page →

30,687
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.22-0+deb10u2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.22-0+deb10u2

Open the chart page →

11,554
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
postgresql-15@15.3-0+deb12u1
15.6-0+deb12u1

Open the chart page →

20,223
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
postgresql14@14.10-r0
14.11-r0

Open the chart page →

1,447
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1

Open the chart page →

12,655
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
postgresql-13@13.13-0+deb11u1
13.14-0+deb11u1

Open the chart page →

2,038
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
postgresql15@15.3-r0
15.6-r0

Open the chart page →

21,005
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
library/node:16.20f77a1aef2da8
postgresql-11@11.20-0+deb10u1
11.22-0+deb10u2
samajh/alprbackend:latestea742b4372ad
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
samajh/alprfrontend:latest05ef4fddbb75
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2

Open the chart page →

20,270
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1

Open the chart page →

3,164
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
postgresql-15@15.5-0+deb12u1
15.6-0+deb12u1

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.6-0+deb12u1

Open the chart page →

14,358
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.22-0+deb10u2

Open the chart page →

5,514
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1

Open the chart page →

3,392
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
postgresql-11@11.12-0+deb10u1
11.22-0+deb10u2

Open the chart page →

2,670
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1

Open the chart page →

1,585
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1

Open the chart page →

1,838

Container images carrying it

223 by charts deploying them

A fixed version is listed for 12 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
camptocamp/ekorre:0.1.035c91d5fda04
postgresql-11@11.5-1+deb10u1
11.22-0+deb10u2
1
cdignam/kodiak:v0.54.05a6a55b39cee
postgresql-11@11.4-1
11.22-0+deb10u2
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
postgresql-11@11.5-1+deb10u1
11.22-0+deb10u2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postgresql-11@11.17-0+deb10u1
11.22-0+deb10u2
1
dacinfomotion/h2p:latest68fa393b472c
postgresql-11@11.20-0+deb10u1
11.22-0+deb10u2
1
danuk/telegram-sender:0.0.1026560388070
postgresql-13@13.8-0+deb11u1
13.14-0+deb11u1
1
douz/helpdesk:latest4384103d0219
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
erlangsolutions/wombatoam:4.1.284680c990147a
postgresql-13@13.8-0+deb11u1
13.14-0+deb11u1
1
evgkrsk/postgres-controller:0.6.237f0e1f435c3
postgresql15@15.1-r0
15.6-r0
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
fanzynoodle/smeejas:0.0.15f9916c1a287
postgresql-13@13.5-0+deb11u1
13.14-0+deb11u1
1
firefart/requesttracker:5.0.40d6249906d8c
postgresql-15@15.3-0+deb12u1
15.6-0+deb12u1
1
fireflyiii/core:version-5.6.142f4283bd0cf7
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
1
fluent/fluent-bit:2.2.00fa18c71d821
postgresql-13@13.11-0+deb11u1
13.14-0+deb11u1
1
fluent/fluent-bit:2.15766d881ddb1
postgresql-13@13.11-0+deb11u1
13.14-0+deb11u1
1
fluent/fluent-bit:2.1.96a1d0c693dfa
postgresql-13@13.11-0+deb11u1
13.14-0+deb11u1
1
fossology/fossology:4.2.18bd1f22ba7bb
postgresql-11@11.18-0+deb10u1
11.22-0+deb10u2
1
galaxy/galaxy-stable:v18.018e577a626dfd
postgresql-9.3@9.3.22-0ubuntu0.14.04
no fix listed
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
postgresql-10@10.14-0ubuntu0.18.04.1
no fix listed
1
gollumorg/gollum:latest7cd5305a3cf7
postgresql-11@11.9-0+deb10u1
11.22-0+deb10u2
1
ha33ona/python:test6affdfc644d0
postgresql-13@13.5-0+deb11u1
13.14-0+deb11u1
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
postgresql-13@13.10-0+deb11u1
13.14-0+deb11u1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
postgresql-15@15.3-0+deb12u1
15.6-0+deb12u1
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
postgresql-10@10.15-0ubuntu0.18.04.1
no fix listed
1
improwised/erpnext-worker:v13.4.197280b55cbd4
postgresql-11@11.12-0+deb10u1
11.22-0+deb10u2
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
postgresql-15@15.5-0+deb12u1
15.6-0+deb12u1
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
postgresql-13@13.11-0+deb11u1
13.14-0+deb11u1
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
postgresql-11@11.12-0+deb10u1
11.22-0+deb10u2
1
kobotoolbox/kobocat:2.022.24ab15679454415
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
library/drupal:8-apache8a1a3ee83899
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
1
library/nextcloud:17.0.0-apache96104cb965fc
postgresql-11@11.5-1+deb10u1
11.22-0+deb10u2
1
library/node:16.20f77a1aef2da8
postgresql-11@11.20-0+deb10u1
11.22-0+deb10u2
1
library/postgres:13.703652c675ae1
postgresql-13@13.7-1.pgdg110+1
13.14-0+deb11u1
1
library/postgres:13.11-bullseye5c265bf1fd30
postgresql-13@13.11-1.pgdg110+1
13.14-0+deb11u1
1
library/postgres:15.38775adb39f0d
postgresql-15@15.3-1.pgdg120+1
15.6-0+deb12u1
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
postgresql15@15.2-r0
15.6-r0
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
postgresql-11@11.13-0+deb10u1
11.22-0+deb10u2
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
postgresql-11@11.13-0+deb10u1
11.22-0+deb10u2
1
lsstsqre/kafkaaggregator:masterbe1b21060854
postgresql-11@11.10-0+deb10u1
11.22-0+deb10u2
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
postgresql-12@12.9-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
lsstsqre/squash-api:0.5.34879415ec6ac
postgresql-11@11.9-0+deb10u1
11.22-0+deb10u2
1
maissacrement/pock8snodejs:0.0.16da0db1159da
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
postgresql-13@13.5-0+deb11u1
13.14-0+deb11u1
1
matrixdotorg/synapse:v1.78.0def97fd537d8
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
mediagis/nominatim:3.7c15e941485ef
postgresql-12@12.12-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
mediagis/nominatim:4.2d0eae7b51374
postgresql-14@14.10-0ubuntu0.22.04.1
14.11-0ubuntu0.22.04.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.