StackRadar

CVE-2024-23337

Medium

Advisory

Published 21 May 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
203
of 17,781 indexed, latest versions
Container images
148
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 203 of 17,781 indexed charts deploy, on 148 images.

Affected packageAffected versionsFixed inImages
jqdeb1.5+dfsg-1, 1.5+dfsg-1ubuntu0.1, 1.5+dfsg-2, 1.6-1ubuntu0.20.04.1+5 more1.5+dfsg-1ubuntu0.1+esm3, 1.5+dfsg-2ubuntu0.1~esm1, 1.6-1ubuntu0.20.04.1+esm1, 1.6-2.1ubuntu3.1+1 more147
jqapk1.7.1-r01.8.0-r01
OSV records
ALPINE-CVE-2024-23337DEBIAN-CVE-2024-23337UBUNTU-CVE-2024-23337
Also known as
USN-7657-1, USN-7657-2

Charts affected

203 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-23337.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.1

Open the chart page →

9,347
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-23337.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.1

Open the chart page →

13,459
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-23337.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1

Open the chart page →

28,605

Container images carrying it

148 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm3
11
library/mongo:5.0.6-focal8e70544b6c76
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
10
oomk8s/readiness-check:2.0.07daa08b81954
jq@1.5+dfsg-1
1.5+dfsg-1ubuntu0.1+esm3
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
jq@1.6-2.1
no fix listed
5
library/mongo:4.44be76f674fc4
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm3
4
library/mongo:5.0-focal5e15a3f014ed
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
4
library/mongo:4.2.12-bionic628741415fc9
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm1
4
library/mongo:4.4.66efa05203990
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm1
4
bitnamilegacy/kubectl:latestcd354d5b2556
jq@1.6-2.1
no fix listed
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
jq@1.6-2.1
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
3
gchq/hdfs:3.3.35ec58edbb2db
jq@1.7.1-3build1
1.7.1-3ubuntu0.24.04.1
3
selenium/hub:3.141.5902f251d48d5f
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.1
3
apache/nifi-registry:1.26.07cdfd8deec92
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.1
2
library/mongo:5.041108d183e97
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
2
library/mongo:4.2.358b25d51baa1
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm1
2
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
jq@1.6-2.1+deb12u1
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
jq@1.6-2.1+deb12u2
no fix listed
1
airbyte/pod-sweeper:1.5.198d2c39d512e
jq@1.6-2.1
no fix listed
1
apache/nifi-registry:1.27.063b8e3e40742
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.1
1
aristidetm/basic-notebook:3.6.5469dbc951224
jq@1.6-2.1
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
1
bitnamilegacy/kubectl:1.301249fc292e84
jq@1.6-2.1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
jq@1.6-2.1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
jq@1.6-2.1
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
jq@1.6-2.1
no fix listed
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
jq@1.6-2.1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
jq@1.6-2.1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
jq@1.6-2.1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
jq@1.6-2.1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
jq@1.6-2.1
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
jq@1.6-2.1ubuntu3
1.6-2.1ubuntu3.1
1
circleci/runner:launch-agent9bdc62f02162
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
1
cribl/cribl:3.0.2762747cb6796
jq@1.5+dfsg-2
1.5+dfsg-2ubuntu0.1~esm1
1
dobtc/bitcoin:25.1a870f7cb1105
jq@1.6-2.1
no fix listed
1
falcosecurity/falco-driver-loader:0.44.17df783d5269a
jq@1.6-2.1+deb12u1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
jq@1.6-2.1+deb12u1
no fix listed
1
free5gmano/nextepc-mongodb:latest36f806935519
jq@1.5+dfsg-1ubuntu0.1
1.5+dfsg-1ubuntu0.1+esm3
1
gradiant/open5gs-dbctl:0.10.3332031245fce
jq@1.7.1-3build1
1.7.1-3ubuntu0.24.04.1
1
haugene/transmission-openvpn:4.0059216cfae4b
jq@1.6-1ubuntu0.20.04.1
1.6-1ubuntu0.20.04.1+esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.