CVE-2024-10963
HighAdvisory
Published 7 Nov 2024In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.4
- base score, highest
- EPSS
- 0.008
- 54th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 115
- of 17,781 indexed, latest versions
- Container images
- 119
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: pam security update
Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 119 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pamdeb | 1.5.3-5ubuntu5, 1.5.3-5ubuntu5.1, 1.5.3-5ubuntu5.4 | 1.5.3-5ubuntu5.5 | 105 |
| pamrpm | 1.3.0-lp151.7.38, 1.5.1-12.el9, 1.5.1-14.el9, 1.5.1-15.el9+2 more | 0:1.5.1-22.el9_5, 0:1.5.1-23.el9_4, 1.7.0-2.1 | 14 |
- OSV records
- RHSA-2024:10232RHSA-2024:10244UBUNTU-CVE-2024-10963openSUSE-SU-2024:14563-1RLSA-2024:10244
- Also known as
- USN-7761-1
Charts affected
115 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| radar-push-endpointradar-baseVerified publisher | 0.6.8 | 1 of 2See more | 3,018 |
| s3-proxyradar-baseVerified publisher | 0.6.0 | 1 of 1See more | 2,737 |
| devtron-enterpriseromholdings | 48.0.0 | 4 of 28See more | 68,240 |
| devtron-operatorromholdings | 0.23.3 | 3 of 11See more | 32,902 |
| snipeitschmitzis | 6.1.0 | 1 of 2See more | 6,094 |
| mongosyncsinextraVerified publisher | 0.4.0 | 1 of 1See more | 2,815 |
| datadogspartan | 0.1.0 | 1 of 1See more | 3,232 |
| nethermindstakewise | 2.8.2 | 1 of 3See more | 2,031 |
| teku-validatorstakewise | 4.3.2 | 1 of 2See more | 3,153 |
| group-challengesubshell-labVerified publisher | 2.1.0 | 1 of 2See more | 2,540 |
| substra-backendsubstraVerified publisher | 26.15.3 | 1 of 7See more | 4,731 |
| stash-boxswuuper-githubVerified publisher | 0.1.1 | 1 of 2See more | 8,193 |
| opencloudunxwaresVerified publisher | 0.2.3 | 1 of 13See more | 45,239 |
| calibre-webvista | 0.1.3 | 1 of 1See more | 7,628 |
| xlinexline | 0.0.1 | 1 of 1See more | 2,097 |
Container images carrying it
119 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | e6c593fe75eb | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | fa99ed475f03 | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | a8ec2f74c9d0 | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | 9deda7b68c34 | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | 89969b78fb07 | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | d7bdfa7b41da | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | 21967f54ec86 | pam | 1.5.3-5ubuntu5.5 | 1 |
| ghcr.io/ | 9d01bf9c9224 | pam | 1.5.3-5ubuntu5.5 | 1 |
| public.ecr.aws/ | 9083e60c38bc | pam | 0:1.5.1-22.el9_5 | 1 |
| public.ecr.aws/ | d7c3def9252b | pam | 0:1.5.1-22.el9_5 | 1 |
| public.ecr.aws/ | 794b3bff9510 | pam | 0:1.5.1-23.el9_4 | 1 |
| quay.io/ | 70d138997acd | pam | 0:1.5.1-23.el9_4 | 1 |
| quay.io/ | 95b5cf7ba6fe | pam | 1.5.3-5ubuntu5.5 | 1 |
| quay.io/ | a36ab0c0860c | pam | 1.5.3-5ubuntu5.5 | 1 |
| quay.io/ | 858f807ea4e2 | pam | 1.5.3-5ubuntu5.5 | 1 |
| quay.io/ | 7932d656b63f | pam | 1.5.3-5ubuntu5.5 | 1 |
| quay.io/ | 8a1361fa38c1 | pam | 0:1.5.1-22.el9_5 | 1 |
| quay.io/ | 59fe607dfdf2 | pam | 0:1.5.1-23.el9_4 | 1 |
| quay.io/ | 7b4202c25b67 | pam | 0:1.5.1-22.el9_5 | 1 |