StackRadar

CVE-2024-0985

High

Advisory

Published 8 Feb 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
222
of 17,781 indexed, latest versions
Container images
223
deployed by those charts
Fix available
12 of 14
affected packages

PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL

Carried by container images the latest versions of 222 of 17,781 indexed charts deploy, on 223 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u115.6-0+deb12u128
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+1 more12.18-0ubuntu0.20.04.116
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+2 more14.11-0ubuntu0.22.04.19
postgresql15apk15.1-r0, 15.2-r0, 15.3-r0, 15.4-r0+1 more15.6-r09
postgresqlbitnami14.4.0-0, 14.4.0-11, 15.2.0-4, 15.3.0-3+3 more12.18.07
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql14apk14.4-r0, 14.5-r0, 14.10-r014.11-r06
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-4212.18.04
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.049.5.25-0ubuntu0.16.04.1+esm73
postgresqlrpm13.23-1.el9_70:15.6-1.module+el9.3.0+21283+b0ea34b61
postgresql16apk16.1-r016.2-r01
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresql-13deb13.3-1, 13.4-0+deb11u1, 13.5-0+deb11u1, 13.6-1.pgdg110+1+8 more13.14-0+deb11u176
postgresql-11deb11.4-1, 11.5-1+deb10u1, 11.7-0+deb10u1, 11.9-0+deb10u1+11 more11.22-0+deb10u260
OSV records
ALPINE-CVE-2024-0985BIT-postgresql-2024-0985DEBIAN-CVE-2024-0985RHSA-2024:0950UBUNTU-CVE-2024-0985DLA-3764-1DSA-5622-1
Also known as
DSA-5623-1, USN-6656-1, USN-6656-2

Charts affected

222 by stars
ChartLatestAffected imagesRadar Score
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.22-0+deb10u2

Open the chart page →

3,313
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
postgresql-13@13.7-1.pgdg110+1
13.14-0+deb11u1

Open the chart page →

2,637
backendsignalen4.24.01 of 4See more

backend signalen 4.24.0

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
12.18.0

Open the chart page →

11,636
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
postgresql-11@11.7-0+deb10u1
11.22-0+deb10u2

Open the chart page →

8,694
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
postgresql-13@13.10-0+deb11u1
13.14-0+deb11u1

Open the chart page →

7,574
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
postgresql-12@12.11-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1

Open the chart page →

30,687
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.22-0+deb10u2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postgresql-11@11.16-0+deb10u1
11.22-0+deb10u2

Open the chart page →

11,554
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
postgresql-15@15.3-0+deb12u1
15.6-0+deb12u1

Open the chart page →

20,223
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
postgresql14@14.10-r0
14.11-r0

Open the chart page →

1,447
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1

Open the chart page →

12,655
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
postgresql-13@13.13-0+deb11u1
13.14-0+deb11u1

Open the chart page →

2,038
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
postgresql15@15.3-r0
15.6-r0

Open the chart page →

21,005
vehicle-dashboardtest-vehi-dash0.1.03 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

3 of the 7 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
library/node:16.20f77a1aef2da8
postgresql-11@11.20-0+deb10u1
11.22-0+deb10u2
samajh/alprbackend:latestea742b4372ad
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
samajh/alprfrontend:latest05ef4fddbb75
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2

Open the chart page →

20,270
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1

Open the chart page →

3,164
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
postgresql-15@15.5-0+deb12u1
15.6-0+deb12u1

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.6-0+deb12u1

Open the chart page →

14,358
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
postgresql-11@11.10-0+deb10u1
11.22-0+deb10u2

Open the chart page →

5,514
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1

Open the chart page →

3,392
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
postgresql-11@11.12-0+deb10u1
11.22-0+deb10u2

Open the chart page →

2,670
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1

Open the chart page →

1,585
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2024-0985.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1

Open the chart page →

1,838

Container images carrying it

223 by charts deploying them

A fixed version is listed for 12 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
postgresql14@14.5-r0
14.11-r0
1
mnaggar3396/python-app:latest371d8ed84b15
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
moreillon/api-proxy:2373c1953739ef6956b5
postgresql-11@11.20-0+deb10u1
11.22-0+deb10u2
1
moreillon/camera-proxy:latestce60056b50c2
postgresql-11@11.20-0+deb10u1
11.22-0+deb10u2
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
postgresql-13@13.5-0+deb11u1
13.14-0+deb11u1
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
postgresql-11@11.18-0+deb10u1
11.22-0+deb10u2
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
postgresql-15@15.5-0+deb12u1
15.6-0+deb12u1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
postgresql-11@11.7-0+deb10u1
11.22-0+deb10u2
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
postgresql-13@13.8-0+deb11u1
13.14-0+deb11u1
1
netboxcommunity/netbox:v3.2.83d652dca5351
postgresql-14@14.4-0ubuntu0.22.04.1
14.11-0ubuntu0.22.04.1
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
postgresql-9.5@9.5.14-0ubuntu0.16.04
9.5.25-0ubuntu0.16.04.1+esm7
1
opendatacube/pipelines:wofs-1.225d810e8504b8
postgresql-10@10.6-0ubuntu0.18.04.1
no fix listed
1
opendatacube/restcube:latest91870111837c
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
postgresql-10@10.10-0ubuntu0.18.04.1
no fix listed
1
openelevation/open-elevation:latest82fb21612e86
postgresql-12@12.7-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
openkm/openkm-ce:6.3.113bc465a7461b
postgresql-12@12.12-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
postgresql-11@11.7-0+deb10u1
11.22-0+deb10u2
1
openzaak/open-notificaties:1.3.02e65313b9b10
postgresql-13@13.5-0+deb11u1
13.14-0+deb11u1
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
postgresql-13@13.5-0+deb11u1
13.14-0+deb11u1
1
oxfordsemantic/rdfox:5.6db17910eb855
postgresql-12@12.9-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
postgresql-12@12.9-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
patdada/bella-docker:v1.0.075127147a624
postgresql-11@11.19-0+deb10u1
11.22-0+deb10u2
1
pecan/monitor:1.7.273b2074f3fec
postgresql-11@11.7-0+deb10u1
11.22-0+deb10u2
1
pecan/web:1.7.2814d678c5550
postgresql-13@13.4-0+deb11u1
13.14-0+deb11u1
1
pgpool/pgpool:latest3782cbf9bb0c
postgresql15@15.2-r0
15.6-r0
1
phntom/email-manager:0.1.22d8e2a9f2f085
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
phntom/external-dns-host-network:0.0.123adadbac8443
postgresql-13@13.8-0+deb11u1
13.14-0+deb11u1
1
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
postgresql15@15.1-r0
15.6-r0
1
plumdog/db-operator:latest0c2fa2db0357
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
postgresql14@14.5-r0
14.11-r0
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
12.18-0ubuntu0.20.04.1
1
redash/redash:10.0.0.b503639392753c0376
postgresql-11@11.12-0+deb10u1
11.22-0+deb10u2
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
rlex/jsonvisio:1.9.5cd50ff65118e
postgresql-11@11.16-0+deb10u1
11.22-0+deb10u2
1
roadiehq/community-backstage-image:latestef355bf5b639
postgresql-11@11.12-0+deb10u1
11.22-0+deb10u2
1
robmarkcole/deepstack-ui:latest410275726459
postgresql-13@13.3-1
13.14-0+deb11u1
1
robotshop/rs-payment:latest774b52c6180d
postgresql-13@13.3-1
13.14-0+deb11u1
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
postgresql-13@13.7-0+deb11u1
13.14-0+deb11u1
1
samajh/alprbackend:latestea742b4372ad
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
1
samajh/alprfrontend:latest05ef4fddbb75
postgresql-11@11.14-0+deb10u1
11.22-0+deb10u2
1
shlomibendavid/k8s-applier:0311240529a22ffbe0f04e
postgresql-11@11.22-0+deb10u1
11.22-0+deb10u2
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/classification_train:0.1.207477060bba8
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
postgresql-13@13.9-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
postgresql-13@13.10-0+deb11u1
13.14-0+deb11u1
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
postgresql-13@13.11-0+deb11u1
13.14-0+deb11u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.