StackRadar

CVE-2024-10963

High

Advisory

Published 7 Nov 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
119
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: pam security update

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 119 images.

Affected packageAffected versionsFixed inImages
pamdeb1.5.3-5ubuntu5, 1.5.3-5ubuntu5.1, 1.5.3-5ubuntu5.41.5.3-5ubuntu5.5105
pamrpm1.3.0-lp151.7.38, 1.5.1-12.el9, 1.5.1-14.el9, 1.5.1-15.el9+2 more0:1.5.1-22.el9_5, 0:1.5.1-23.el9_4, 1.7.0-2.114
OSV records
RHSA-2024:10232RHSA-2024:10244UBUNTU-CVE-2024-10963openSUSE-SU-2024:14563-1RLSA-2024:10244
Also known as
USN-7761-1

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

3,018
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

2,737
devtron-enterpriseromholdings48.0.04 of 28See more

devtron-enterprise romholdings 48.0.0

4 of the 28 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

68,240
devtron-operatorromholdings0.23.33 of 11See more

devtron-operator romholdings 0.23.3

3 of the 11 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

32,902
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5

Open the chart page →

6,094
mongosyncsinextraVerified publisher0.4.01 of 1See more

mongosync sinextra 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5

Open the chart page →

2,815
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

3,232
nethermindstakewise2.8.21 of 3See more

nethermind stakewise 2.8.2

1 of the 3 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
nethermind/nethermind:1.31.893e57917371a
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

2,031
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

3,153
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5

Open the chart page →

2,540
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

4,731
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5

Open the chart page →

8,193
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
pam@1.5.3-5ubuntu5
1.5.3-5ubuntu5.5

Open the chart page →

45,239
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5

Open the chart page →

7,628
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-10963.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
pam@1.5.3-5ubuntu5
1.5.3-5ubuntu5.5

Open the chart page →

2,097

Container images carrying it

119 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
pam@1.5.1-20.el9
0:1.5.1-22.el9_5
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
pam@1.5.1-20.el9
0:1.5.1-22.el9_5
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
pam@1.5.1-19.el9
0:1.5.1-23.el9_4
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
pam@1.5.1-19.el9
0:1.5.1-23.el9_4
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
pam@1.5.3-5ubuntu5.1
1.5.3-5ubuntu5.5
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
pam@1.5.3-5ubuntu5.4
1.5.3-5ubuntu5.5
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
pam@1.5.1-19.el9
0:1.5.1-22.el9_5
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pam@1.5.1-19.el9
0:1.5.1-23.el9_4
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
pam@1.5.1-14.el9
0:1.5.1-22.el9_5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.