CVE-2024-13176
MediumAdvisory
Published 20 Jan 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.1
- base score, highest
- EPSS
- 0.006
- 48th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,375
- of 17,805 indexed, latest versions
- Container images
- 2,697
- deployed by those charts
- Fix available
- 2 of 5
- affected packages
openssl - security update
Carried by container images the latest versions of 2,375 of 17,805 indexed charts deploy, on 2,697 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+92 more | 1.1.1f-1ubuntu2.24, 1.1.1f-1ubuntu2.fips.24, 1.1.1w-0+deb11u3, 3.0.2-0ubuntu1.19+2 more | 1,778 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+38 more | 3.0.19-r0, 3.1.8-r0, 3.3.2-r2, 3.3.2-r5+1 more | 918 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more | no fix listed | 20 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
| edk2deb | 2022.11-6+deb12u2 | no fix listed | 1 |
- OSV records
- ALPINE-CVE-2024-13176CGA-82rc-p89h-xq36DEBIAN-CVE-2024-13176UBUNTU-CVE-2024-13176DLA-4176-1
- Also known as
- CGA-qxwv-h54f-gwqm, USN-7278-1
Charts affected
2,375 by stars
Container images carrying it
2,697 by charts deploying them
A fixed version is listed for 2 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | d7f76c9c65d9 | openssl | 3.3.2-r5 | 1 |
| ghcr.io/ | f7e607f24071 | openssl | 3.0.16-1~deb12u1 | 1 |
| ghcr.io/ | 7dc0ee57b628 | openssl | 3.0.16-1~deb12u1 | 1 |
| ghcr.io/ | ae9ae0925ff8 | openssl | no fix listed | 1 |
| mcr.microsoft.com/ | bccaa701e2df | openssl | 1.1.1f-1ubuntu2.24 | 1 |
| mcr.microsoft.com/ | 13221ac5f673 | openssl openssl1.0 | no fix listed no fix listed | 1 |
| mcr.microsoft.com/ | 49a57dc220b1 | openssl | 1.1.1f-1ubuntu2.24 | 1 |
| mcr.microsoft.com/ | ba4c8329f48f | openssl | no fix listed | 1 |
| mcr.microsoft.com/ | fbf79e0fea59 | openssl openssl1.0 | no fix listed no fix listed | 1 |
| mcr.microsoft.com/ | 77788bf38938 | openssl | 1.1.1w-0+deb11u3 | 1 |
| public.ecr.aws/ | 1eb61443d68e | openssl | 3.3.2-r2 | 1 |
| public.ecr.aws/ | af66e52f852a | openssl | 3.1.8-r0 | 1 |
| public.ecr.aws/ | ffc29318c5e9 | openssl | 3.1.8-r0 | 1 |
| public.ecr.aws/ | 873c49204b64 | openssl | 3.1.8-r0 | 1 |
| public.ecr.aws/ | ee9d973e3952 | openssl | no fix listed | 1 |
| public.ecr.aws/ | cac3ed9a9826 | openssl | 1.1.1w-0+deb11u3 | 1 |
| public.ecr.aws/ | abd817eb6845 | openssl | 1.1.1w-0+deb11u3 | 1 |
| public.ecr.aws/ | b1493760c716 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 34823c8abe00 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 56efd38500d6 | openssl | 1.1.1w-0+deb11u3 | 1 |
| public.ecr.aws/ | 5cd62142d6ed | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | f8fb4eea4071 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 36d051110158 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 9e14a72b066d | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 71697b5ff713 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | f7567ce3419d | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | efcecf98b912 | openssl | no fix listed | 1 |
| public.ecr.aws/ | 573779e57fae | openssl | 1.1.1f-1ubuntu2.24 | 1 |
| public.ecr.aws/ | 077e4e57e41c | openssl | 1.1.1w-0+deb11u3 | 1 |
| public.ecr.aws/ | f74851ce31f5 | openssl | 3.0.16-1~deb12u1 | 1 |
| public.ecr.aws/ | 27f8de509169 | openssl | 3.0.16-1~deb12u1 | 1 |
| quay.io/ | 70fd7c00418d | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | 578934444f04 | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | 5b6701d8fb31 | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | acaf37352569 | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | 14b482c1f1b8 | openssl | 1.1.1w-0+deb11u3 | 1 |
| quay.io/ | 351d6685dc6f | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | 96fac2482898 | openssl | 3.1.8-r0 | 1 |
| quay.io/ | a9f835d1b241 | openssl | 3.0.16-1~deb12u1 | 1 |
| quay.io/ | fe2e2e5a2751 | openssl | 3.1.8-r0 | 1 |
| quay.io/ | d9f0bec83ef0 | openssl | no fix listed | 1 |
| quay.io/ | a2d3a4c67b0f | openssl | no fix listed | 1 |
| quay.io/ | 60950ef63764 | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | d53cb940196c | openssl | 3.1.8-r0 | 1 |
| quay.io/ | 0cca71497e9e | openssl | 3.0.19-r0 | 1 |
| quay.io/ | cd36290dc849 | openssl | 3.1.8-r0 | 1 |
| quay.io/ | 93889c3d8a34 | openssl | 3.0.2-0ubuntu1.19 | 1 |
| quay.io/ | 99079df58561 | openssl | 1.1.1w-0+deb11u3 | 1 |
| quay.io/ | 5af45ac79f38 | openssl | 1.1.1w-0+deb11u3 | 1 |