StackRadar

CVE-2024-11187

High

Advisory

Published 29 Jan 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.167
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
106
of 17,781 indexed, latest versions
Container images
103
deployed by those charts
Fix available
3 of 5
affected packages

Red Hat Security Advisory: bind security update

Carried by container images the latest versions of 106 of 17,781 indexed charts deploy, on 103 images.

Affected packageAffected versionsFixed inImages
bind9deb1:9.11.3+dfsg-1ubuntu1.1, 1:9.11.3+dfsg-1ubuntu1.12, 1:9.11.3+dfsg-1ubuntu1.13, 1:9.11.3+dfsg-1ubuntu1.14+30 more1:9.16.50-1~deb11u3, 1:9.18.30-0ubuntu0.20.04.2, 1:9.18.30-0ubuntu0.22.04.2, 1:9.18.30-0ubuntu0.24.04.2+1 more73
bindapk9.18.13-r2, 9.18.16-r0, 9.18.19-r0, 9.18.19-r1+3 more9.18.33-r015
bindrpm32:9.11.13-6.el8_2.4, 32:9.11.26-4.el8_4, 32:9.11.26-4.el8_4.1, 32:9.11.36-3.el8_6.5+7 more2:9.11.36-16.el8_10.4, 32:9.11.36-8.el8_8.7, 32:9.11.36-16.el8_10.4, 32:9.16.23-18.el9_4.9+1 more14
bind9-libsdeb1:9.11.19+dfsg-2.1ubuntu3no fix listed1
isc-dhcpdeb4.3.5-3ubuntu7.1no fix listed1
OSV records
ALPINE-CVE-2024-11187DEBIAN-CVE-2024-11187RHSA-2025:1666RHSA-2025:1669RHSA-2025:1675RHSA-2025:1681UBUNTU-CVE-2024-11187DLA-4050-1RLSA-2025:1675
Also known as
RHSA-2025:1684, RHSA-2025:1687, RHSA-2025:1691, USN-7241-1

Charts affected

106 by stars
ChartLatestAffected imagesRadar Score
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-11187.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
bind9@1:9.18.18-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2

Open the chart page →

5,841
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-11187.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
bind9@1:9.18.1-1ubuntu1.1
1:9.18.30-0ubuntu0.22.04.2

Open the chart page →

12,048
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-11187.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
bind9@1:9.16.48-0ubuntu0.20.04.1
1:9.18.30-0ubuntu0.20.04.2

Open the chart page →

18,756
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-11187.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
bind@9.18.19-r1
9.18.33-r0

Open the chart page →

2,336
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2024-11187.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
bind9@1:9.16.33-1~deb11u1
1:9.16.50-1~deb11u3

Open the chart page →

8,607
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2024-11187.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
bind9@1:9.16.1-0ubuntu2.9
1:9.18.30-0ubuntu0.20.04.2

Open the chart page →

15,230

Container images carrying it

103 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
bind@9.18.24-r0
9.18.33-r0
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
bind9@1:9.18.28-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
bind9@1:9.18.28-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
bind9@1:9.18.28-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
bind9@1:9.18.28-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2
1
snipe/snipe-it:v6.0.1455fb7636a98c
bind9@1:9.16.1-0ubuntu2.11
1:9.18.30-0ubuntu0.20.04.2
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
stackstorm/st2actionrunner:3.888235ba70cad
bind9@1:9.16.1-0ubuntu2.16
1:9.18.30-0ubuntu0.20.04.2
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
bind9@1:9.18.24-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
bind9@1:9.18.18-0ubuntu0.22.04.1
1:9.18.30-0ubuntu0.22.04.2
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
bind9@1:9.16.48-0ubuntu0.20.04.1
1:9.18.30-0ubuntu0.20.04.2
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
bind@9.18.19-r1
9.18.33-r0
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
bind9@1:9.18.30-0ubuntu0.20.04.2
no fix listed
1
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
bind9@1:9.16.27-1~deb11u1
1:9.16.50-1~deb11u3
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
bind@32:9.11.36-5.el8_7.2
2:9.11.36-16.el8_10.4
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
bind9@1:9.18.19-1~deb12u1
1:9.18.33-1~deb12u2
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
bind9@1:9.16.27-1~deb11u1
1:9.16.50-1~deb11u3
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
bind@9.18.19-r0
9.18.33-r0
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
bind@32:9.16.23-14.el9_3
32:9.16.23-24.el9_5.3
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
bind9@1:9.18.28-0ubuntu0.24.04.1
1:9.18.30-0ubuntu0.24.04.2
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
bind9@1:9.16.1-0ubuntu2.9
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
bind9@1:9.16.1-0ubuntu2.8
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
bind9@1:9.18.1-1ubuntu1.1
1:9.18.30-0ubuntu0.22.04.2
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
bind9@1:9.18.1-1ubuntu1.1
1:9.18.30-0ubuntu0.22.04.2
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
bind9@1:9.18.1-1ubuntu1.1
1:9.18.30-0ubuntu0.22.04.2
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
bind9@1:9.16.1-0ubuntu2.8
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
bind9@1:9.16.1-0ubuntu2.15
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
bind9@1:9.11.3+dfsg-1ubuntu1.18
no fix listed
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
bind9@1:9.18.30-0ubuntu0.20.04.2
no fix listed
1
ghcr.io/luzilla/unbound:v0.7.0-rc3252613692e5e
bind@9.18.24-r1
9.18.33-r0
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
bind@9.18.19-r1
9.18.33-r0
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
bind@9.18.13-r2
9.18.33-r0
1
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
bind@9.18.19-r1
9.18.33-r0
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
bind@9.18.19-r1
9.18.33-r0
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
bind@9.18.19-r1
9.18.33-r0
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
bind9@1:9.16.1-0ubuntu2.10
1:9.18.30-0ubuntu0.20.04.2
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
bind@9.18.19-r0
9.18.33-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
bind9@1:9.18.18-0ubuntu0.22.04.2
1:9.18.30-0ubuntu0.22.04.2
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
bind@32:9.11.36-16.el8_10.2
32:9.11.36-16.el8_10.4
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
bind@32:9.11.36-8.el8_8.1
32:9.11.36-8.el8_8.7
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
bind@32:9.11.26-4.el8_4
32:9.11.36-16.el8_10.4
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
bind9@1:9.16.44-1~deb11u1
1:9.16.50-1~deb11u3
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
bind9@1:9.16.33-1~deb11u1
1:9.16.50-1~deb11u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.