StackRadar

CVE-2024-24758

Medium

Advisory

Published 16 Feb 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.5
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
25
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 2
affected packages

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

Carried by container images the latest versions of 25 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2no fix listed8
undicinpm4.15.0, 5.0.0, 5.6.0, 5.11.0+8 more5.28.322
OSV records
DEBIAN-CVE-2024-24758GHSA-3787-6prv-h9w3UBUNTU-CVE-2024-24758

Charts affected

25 by stars
ChartLatestAffected imagesRadar Score
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
5.28.3

Open the chart page →

10,311
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

20,403
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
undici@5.22.0
5.28.3

Open the chart page →

9,783
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
undici@5.22.1
5.28.3

Open the chart page →

4,083
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

6,998
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-undici@5.26.3+dfsg1+~cs23.10.12-2
undici@5.26.3
no fix listed
5.28.3

Open the chart page →

13,220
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
undici@5.0.0
5.28.3

Open the chart page →

3,769
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

19,224
dominodomino-iisasVerified publisher0.3.11 of 3See more

domino domino-iisas 0.3.1

1 of the 3 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ghcr.io/iisas/domino-frontend:k8s8e53861be292
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

10,270
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

9,244
evobotevobotVerified publisher0.1.11 of 1See more

evobot evobot 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
undici@5.27.2
5.28.3

Open the chart page →

2,987
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

13,241
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
undici@5.22.1
5.28.3

Open the chart page →

9,019
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
5.28.3

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
5.28.3

Open the chart page →

2,682
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
undici@4.15.0
5.28.3

Open the chart page →

4,944
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3

Open the chart page →

10,780
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
undici@5.22.0
5.28.3

Open the chart page →

9,783
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
undici@5.22.1
5.28.3

Open the chart page →

2,178
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
undici@5.22.1
5.28.3

Open the chart page →

4,960
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
undici@5.28.2
5.28.3

Open the chart page →

6,282
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
undici@5.11.0
5.28.3

Open the chart page →

2,267
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
undici@5.26.3
5.28.3

Open the chart page →

14,679
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
5.28.3

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-24758.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
5.28.3

Open the chart page →

4,017

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
5.28.3
3
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
undici@5.22.0
5.28.3
2
cryptexlabs/authf:0.12.11189c07411d7c
undici@5.0.0
5.28.3
1
deconzcommunity/deconz:2.29.2062de2362641
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
undici@4.15.0
5.28.3
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-undici@5.26.3+dfsg1+~cs23.10.12-2
undici@5.26.3
no fix listed
5.28.3
1
kubebb/component-store:latestfd8ecbd73213
undici@5.22.1
5.28.3
1
langgenius/dify-api:1.0.0066035f93856
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3
1
langgenius/dify-api:0.6.11fca918260dd6
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3
undici@5.15.0
no fix listed
5.28.3
1
library/ghost:6.25.12654b1e90413
undici@5.22.1
5.28.3
1
library/ghost:5.79.083f7bf209844
undici@5.22.1
5.28.3
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
undici@5.22.1
5.28.3
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3
1
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
5.28.3
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1
undici@5.15.0
no fix listed
5.28.3
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
undici@5.26.3
5.28.3
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
5.28.3
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
undici@5.27.2
5.28.3
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
5.28.3
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
undici@5.28.2
5.28.3
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
undici@5.11.0
5.28.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.