StackRadar

CVE-2024-2004

Low

Advisory

Published 27 Mar 2024In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
289
of 17,781 indexed, latest versions
Container images
270
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 289 of 17,781 indexed charts deploy, on 270 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+12 more8.7.1-r0186
curldeb7.88.1-10, 7.88.1-10+deb12u1, 7.88.1-10+deb12u4, 7.88.1-10+deb12u57.88.1-10+deb12u684
OSV records
ALPINE-CVE-2024-2004DEBIAN-CVE-2024-2004

Charts affected

289 by stars
ChartLatestAffected imagesRadar Score
sponge-vanillaschichtelVerified publisher0.1.21 of 1See more

sponge-vanilla schichtel 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
curl@8.3.0-r0
8.7.1-r0

Open the chart page →

1,009
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.7.1-r0
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,881
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,337
serviceexampleserviceexample0.1.01 of 5See more

serviceexample serviceexample 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.7.1-r0

Open the chart page →

5,449
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.7.1-r0

Open the chart page →

2,863
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,825
mimirskyloud-helm-chartsVerified publisher5.5.11 of 5See more

mimir skyloud-helm-charts 5.5.1

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

10,651
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.7.1-r0

Open the chart page →

4,285
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

16,368
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,416
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u6

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

13,390
ingress-nginx-external-lbsuminhong1.0.01 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,094
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
curl@8.4.0-r0
8.7.1-r0

Open the chart page →

1,480
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

9,102
snmp-managersvtech-public-helm-charts1.1.01 of 1See more

snmp-manager svtech-public-helm-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

761
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,336
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
curl@8.4.0-r0
8.7.1-r0

Open the chart page →

1,970
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u6

Open the chart page →

6,297
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.7.1-r0
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.7.1-r0
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.7.1-r0

Open the chart page →

21,005
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

28,858
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,806
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,477
posteetrivy-operator2.14.01 of 3See more

postee trivy-operator 2.14.0

1 of the 3 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.7.1-r0

Open the chart page →

4,815
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u6

Open the chart page →

14,358
demo-frontendv2flyVerified publisher0.0.31 of 1See more

demo-frontend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

753
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.7.1-r0

Open the chart page →

2,635
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
curl@8.4.0-r0
8.7.1-r0

Open the chart page →

4,060
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u6

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.7.1-r0

Open the chart page →

2,030
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

5,542
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6

Open the chart page →

7,673
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,611
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.7.1-r0

Open the chart page →

5,033
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2004.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,589

Container images carrying it

270 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/airflow:2.8.4-python3.964e58748b6b9
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
apache/airflow:2.8.1e5560ad0b86e
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
apache/superset:4.0.1ab9467fd712c
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.7.1-r0
1
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.7.1-r0
1
aquasec/trivy:0.43.1944a04445179
curl@8.1.2-r0
8.7.1-r0
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u6
1
avinash263/pyredis263:latestaa2b8727f1a6
curl@7.88.1-10
7.88.1-10+deb12u6
1
avzini/web-app:latestf40b30210ed0
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u6
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
casbin/casdoor:v1.224.066f836ef778b
curl@7.87.0-r1
8.7.1-r0
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
curl@8.1.2-r0
8.7.1-r0
1
codecov/self-hosted-api:24.4.10475cb1c3136
curl@8.5.0-r0
8.7.1-r0
1
codecov/self-hosted-frontend:24.4.1534bc4778073
curl@8.5.0-r0
8.7.1-r0
1
codecov/self-hosted-worker:24.4.1837f546b479b
curl@8.5.0-r0
8.7.1-r0
1
collabora/code:23.05.10.1.105299b452f7f
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
curl@7.87.0-r0
8.7.1-r0
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u6
1
daledavies/jump:v1.4.10a0c8ad93902
curl@8.5.0-r0
8.7.1-r0
1
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.7.1-r0
1
ddosify/selfhosted_frontend:2.7.456dbd7cf0776
curl@8.5.0-r0
8.7.1-r0
1
ddosify/selfhosted_frontend:4.1.5bf454ab99d89
curl@8.5.0-r0
8.7.1-r0
1
defactops/defactops-ui:1.0.16825cdf9ba706
curl@8.5.0-r0
8.7.1-r0
1
devopstales/trivy-operator:2.575136aa7a26e
curl@7.87.0-r1
8.7.1-r0
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.7.1-r0
1
dnsforge/xteve:latest4d9a685c8c28
curl@7.87.0-r1
8.7.1-r0
1
dobtc/bitcoin:25.1a870f7cb1105
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u6
1
dragonflyoss/client:v0.1.82edf3e921f4e0
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
curl@8.5.0-r0
8.7.1-r0
1
dragonflyoss/scheduler:v2.1.49523785c77787
curl@8.5.0-r0
8.7.1-r0
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
curl@7.88.1-r0
8.7.1-r0
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
curl@8.4.0-r0
8.7.1-r0
1
eqalpha/keydb:alpine_x86_64_v6.3.4f1d60f12cb3c
curl@8.4.0-r0
8.7.1-r0
1
esphome/esphome:2024.3.09ab8cc88b28c
curl@7.88.1-10+deb12u5
7.88.1-10+deb12u6
1
factly/mande-studio:0.34.19db4bee30e63
curl@8.2.1-r0
8.7.1-r0
1
fedodo/fedodo.ui.home:3c69413c4d690
curl@8.1.2-r0
8.7.1-r0
1
fedodo/fedodo.ui.micro:12b2b540081c21
curl@8.1.2-r0
8.7.1-r0
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.7.1-r0
1
felipecs8/qrcode-generator:v1d5f4f17cb066
curl@7.87.0-r1
8.7.1-r0
1
firefart/requesttracker:5.0.40d6249906d8c
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u6
1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
curl@8.1.2-r0
8.7.1-r0
1
folioci/mod-data-import-converter-storage:latest3028f333778f
curl@7.87.0-r0
8.7.1-r0
1
gitea/gitea:1.21.6ac73e0da341f
curl@8.5.0-r0
8.7.1-r0
1
glenndehaan/sunflare-tools:latesta5b3f1dd865d
curl@8.2.1-r0
8.7.1-r0
1
grafana/grafana:10.1.50679e877ba20
curl@8.4.0-r0
8.7.1-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.