CVE-2024-13176
MediumAdvisory
Published 20 Jan 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.1
- base score, highest
- EPSS
- 0.006
- 48th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,343
- of 17,790 indexed, latest versions
- Container images
- 2,675
- deployed by those charts
- Fix available
- 2 of 5
- affected packages
openssl - security update
Carried by container images the latest versions of 2,343 of 17,790 indexed charts deploy, on 2,675 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+92 more | 1.1.1f-1ubuntu2.24, 1.1.1f-1ubuntu2.fips.24, 1.1.1w-0+deb11u3, 3.0.2-0ubuntu1.19+2 more | 1,760 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+38 more | 3.0.19-r0, 3.1.8-r0, 3.3.2-r2, 3.3.2-r5+1 more | 914 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | no fix listed | 15 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| edk2deb | 2022.11-6+deb12u2 | no fix listed | 1 |
- OSV records
- ALPINE-CVE-2024-13176CGA-82rc-p89h-xq36DEBIAN-CVE-2024-13176UBUNTU-CVE-2024-13176DLA-4176-1
- Also known as
- CGA-qxwv-h54f-gwqm, USN-7278-1
Charts affected
2,343 by stars
Container images carrying it
2,675 by charts deploying them
A fixed version is listed for 2 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 0502794a4d86 | openssl | 3.0.16-1~deb12u1 | 3 |
| quay.io/ | 6545dac92173 | openssl | 3.0.16-1~deb12u1 | 3 |
| quay.io/ | 2b6db27eaf3d | openssl | 3.0.2-0ubuntu1.19 | 3 |
| quay.io/ | f6269309455a | openssl | 3.1.8-r0 | 3 |
| quay.io/ | 03c7bf249aa1 | openssl | 3.3.2-r5 | 3 |
| quay.io/ | 39f2c6e0af38 | openssl | 1.1.1f-1ubuntu2.24 | 3 |
| quay.io/ | 98580969b333 | openssl | 3.3.2-r5 | 3 |
| quay.io/ | 4c3b91bebd3d | openssl | no fix listed | 3 |
| quay.io/ | 4286bcccda3e | openssl | 3.1.8-r0 | 3 |
| quay.io/ | f296c2ec5db7 | openssl | 3.0.2-0ubuntu1.19 | 3 |
| quay.io/ | d30a7c640c63 | openssl | 3.3.2-r5 | 3 |
| quay.io/ | eec0305b594c | openssl | 3.1.8-r0 | 3 |
| quay.io/ | e886b8d2b54b | openssl | 3.3.2-r5 | 3 |
| quay.io/ | 9640e2dc4316 | openssl | 3.0.19-r0 | 3 |
| quay.io/ | fd916f75415f | openssl | 3.1.8-r0 | 3 |
| quay.io/ | 1b33357b3595 | openssl | 3.1.8-r0 | 3 |
| registry.k8s.io/ | e5c4824e7375 | openssl | 3.1.8-r0 | 3 |
| 1password/ | 29d0c6cb67eb | openssl | 1.1.1w-0+deb11u3 | 2 |
| agoldis/ | afaa5a84051d | openssl | 3.1.8-r0 | 2 |
| agoldis/ | e061e5714238 | openssl | 3.0.19-r0 | 2 |
| agoldis/ | 10228ecd353b | openssl | 3.1.8-r0 | 2 |
| alpine/ | f0c1b7ca12f6 | openssl | 3.3.2-r2 | 2 |
| apache/ | 7cdfd8deec92 | openssl | 3.0.2-0ubuntu1.19 | 2 |
| apache/ | afe59523a6c8 | openssl | 3.1.8-r0 | 2 |
| apache/ | ae0b86d3c4d0 | openssl | 3.0.13-0ubuntu3.5 | 2 |
| aquasec/ | ea3e33bc3c4e | openssl | 3.3.2-r2 | 2 |
| assistiot/ | ad8f72108636 | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitnamilegacy/ | d17df1f9d745 | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitnamilegacy/ | a0a972324d93 | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitnamilegacy/ | 33ce23601fc9 | openssl | 3.0.16-1~deb12u1 | 2 |
| bitnamilegacy/ | 2cb5982dcbf4 | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitnamilegacy/ | 7e7ebb082031 | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitnamilegacy/ | 94bc968141e7 | openssl | 3.0.16-1~deb12u1 | 2 |
| bitnamilegacy/ | 10ed1ea3c8d1 | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitpoke/ | f44fa86ab27e | openssl | 1.1.1w-0+deb11u3 | 2 |
| bitpoke/ | d86560c75bed | openssl | 1.1.1w-0+deb11u3 | 2 |
| blakeblackshear/ | 8330b0a265b8 | openssl | 1.1.1w-0+deb11u3 | 2 |
| cculianu/ | 6445fb75abea | openssl | 1.1.1w-0+deb11u3 | 2 |
| cfssl/ | c9018c2ddf0b | openssl | 3.0.16-1~deb12u1 | 2 |
| chatwoot/ | d530ab8c1753 | openssl | 3.1.8-r0 | 2 |
| clickhouse/ | ed9640bfff07 | openssl | 1.1.1f-1ubuntu2.24 | 2 |
| clickhouse/ | f226fe41f057 | openssl | 3.1.8-r0 | 2 |
| cs3org/ | 02a9e78757b4 | openssl | 3.0.19-r0 | 2 |
| curlimages/ | 4a3396ae573c | openssl | 3.1.8-r0 | 2 |
| curlimages/ | c3b8bee303c6 | openssl | 3.1.8-r0 | 2 |
| daniacobext/ | 9eae4d39fc33 | openssl | 3.0.19-r0 | 2 |
| datagrok/ | f5876d3aebb8 | openssl | no fix listed | 2 |
| dependencytrack/ | 485ac0952c02 | openssl | 1.1.1w-0+deb11u3 | 2 |
| dtzar/ | 55429449408e | openssl | 3.1.8-r0 | 2 |
| epamedp/ | 687acf641097 | openssl | 3.1.8-r0 | 2 |