StackRadar

CVE-2024-12085

High

Advisory

Published 9 Jan 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.088
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
109
of 17,781 indexed, latest versions
Container images
90
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: rsync security update

Carried by container images the latest versions of 109 of 17,781 indexed charts deploy, on 90 images.

Affected packageAffected versionsFixed inImages
rsyncdeb3.1.0-2ubuntu0.1, 3.1.0-2ubuntu0.4, 3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2+14 more3.1.0-2ubuntu0.4+esm1, 3.1.1-3ubuntu1.3+esm3, 3.1.2-2.1ubuntu1.6+esm1, 3.1.3-8ubuntu0.8+3 more51
rsyncrpm3.1.2-6.el7_6.1, 3.1.3-7.el8, 3.1.3-7.el8_2.2, 3.1.3-12.el8+6 more0:3.1.2-12.el7_9.1, 0:3.1.3-20.el8_10, 0:3.2.3-20.el9_5.137
rsyncapk3.2.7-r43.4.0-r02
OSV records
ALPINE-CVE-2024-12085DEBIAN-CVE-2024-12085RHSA-2025:0324RHSA-2025:0325RHSA-2025:0714UBUNTU-CVE-2024-12085
Also known as
RHSA-2025:0637, RHSA-2025:0774, RHSA-2025:0787, RHSA-2025:0790, RHSA-2025:0884, RHSA-2025:0885, USN-7206-1

Charts affected

109 by stars
ChartLatestAffected imagesRadar Score
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
rsync@3.1.3-14.el8_6.2
0:3.1.3-20.el8_10

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
rsync@3.1.3-14.el8_6.2
0:3.1.3-20.el8_10

Open the chart page →

11,554
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
rsync@3.2.7-1
3.2.7-1+deb12u1

Open the chart page →

9,102
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.8

Open the chart page →

18,756
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10

Open the chart page →

13,719
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
rsync@3.2.7-0ubuntu0.22.04.2
3.2.7-0ubuntu0.22.04.3

Open the chart page →

20,270
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10

Open the chart page →

12,455
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
rsync@3.2.7-0ubuntu0.22.04.2
3.2.7-0ubuntu0.22.04.3

Open the chart page →

13,459
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-12085.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10

Open the chart page →

11,577

Container images carrying it

90 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
rsync@3.2.7-1
3.2.7-1+deb12u1
1
oled01/db-backup:0.1.06302fd2b5333
rsync@3.2.3-8ubuntu3.1
3.2.7-0ubuntu0.22.04.3
1
omecproject/onos-progran:1.0.05715e5648aa0
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm3
1
photoprism/photoprism:240711-cefc6fd632ca74
rsync@3.2.7-1ubuntu1
3.2.7-1ubuntu1.1
1
resouer/redis-slave:v2e2f198b49ba7
rsync@3.1.0-2ubuntu0.1
3.1.0-2ubuntu0.4+esm1
1
rm3l/dev-feed-api:latest9a7f732245a3
rsync@3.2.3-19.el9
0:3.2.3-20.el9_5.1
1
scrapinghub/splash:3.4.1a5f89bc84606
rsync@3.1.2-2.1ubuntu1
3.1.2-2.1ubuntu1.6+esm1
1
seldonio/locust-core:0.81d0da98a2d76
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm3
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10
1
stackstorm/st2actionrunner:3.888235ba70cad
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.8
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
rsync@3.2.7-1
3.2.7-1+deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.8
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm3
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
rsync@3.2.7-0ubuntu0.22.04.2
3.2.7-0ubuntu0.22.04.3
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
rsync@3.2.7-1
3.2.7-1+deb12u1
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
rsync@3.2.3-19.el9
0:3.2.3-20.el9_5.1
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
rsync@3.1.3-8ubuntu0.3
3.1.3-8ubuntu0.8
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
rsync@3.1.3-8
3.1.3-8ubuntu0.8
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
rsync@3.1.3-8
3.1.3-8ubuntu0.8
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
rsync@3.2.3-19.el9
0:3.2.3-20.el9_5.1
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
rsync@3.1.3-14.el8_6.2
0:3.1.3-20.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
rsync@3.1.3-14.el8_6.2
0:3.1.3-20.el8_10
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
rsync@3.1.3-14.el8_6.2
0:3.1.3-20.el8_10
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
rsync@3.1.3-7.el8
0:3.1.3-20.el8_10
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
rsync@3.1.3-12.el8
0:3.1.3-20.el8_10
1
quay.io/openshift/origin-cli:4.66722d5041b47
rsync@3.1.3-7.el8_2.2
0:3.1.3-20.el8_10
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
rsync@3.1.3-14.el8_6.5
0:3.1.3-20.el8_10
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
rsync@3.1.1-3ubuntu1.3
3.1.1-3ubuntu1.3+esm3
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
rsync@3.2.3-19.el9
0:3.2.3-20.el9_5.1
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
rsync@3.1.3-19.el8_7.1
0:3.1.3-20.el8_10
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
rsync@3.2.7-r4
3.4.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.