StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,937
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,232
irods-csi-drivercyverse0.12.03 of 4See more

irods-csi-driver cyverse 0.12.0

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/protobuf@v1.31.0
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,257
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,832
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,209
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,238
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,926
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,041
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,571
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

958
eg-edge-stackdatawire0.0.14 of 7See more

eg-edge-stack datawire 0.0.1

4 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
google.golang.org/protobuf@v1.31.0
1.33.0
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

15,781
eg-edge-stack-crdsdatawire0.0.11 of 2See more

eg-edge-stack-crds datawire 0.0.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,404
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

970
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,583
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,299
aws-service-quotas-exporterdeliveryheroVerified publisher0.1.41 of 1See more

aws-service-quotas-exporter deliveryhero 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

771
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,234
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

1,315
toxiproxydeliveryheroVerified publisher1.3.91 of 2See more

toxiproxy deliveryhero 1.3.9

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

598
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/protobuf@v1.28.0
1.33.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,722
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
google.golang.org/protobuf@v1.23.0
1.33.0
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.11 of 2See more

lxd8s devplayer0 0.5.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,431
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/protobuf@v1.26.0
1.33.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,507
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
google.golang.org/protobuf@v1.23.0
1.33.0
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
google.golang.org/protobuf@v1.28.0
1.33.0
1
gutmensch/podnat-controller:0.5.2566979793fc4
google.golang.org/protobuf@v1.28.1
1.33.0
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
google.golang.org/protobuf@v1.32.0
1.33.0
1
hashicorp/boundary:0.8.1fb70bd9210ff
google.golang.org/protobuf@v1.27.1
1.33.0
1
hashicorp/consul:1.17.0712fe02d2f84
google.golang.org/protobuf@v1.30.0
1.33.0
1
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
google.golang.org/protobuf@v1.30.0
1.33.0
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/terraform:1.44dcb45513699
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/terraform-k8s:1.1.2b19857bab620
google.golang.org/protobuf@v1.26.0
1.33.0
1
hashicorp/vault:1.15.40b01ed3924e6
google.golang.org/protobuf@v1.31.0
1.33.0
1
hashicorp/vault:1.14.0b2177a8bfe85
google.golang.org/protobuf@v1.30.0
1.33.0
1
hashicorp/vault:1.8.4dfc3500beb0e
google.golang.org/protobuf@v1.25.0
1.33.0
1
hashicorp/vault-k8s:1.2.14500e988b7ce
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/vault-k8s:0.6.05697b85bc69a
google.golang.org/protobuf@v1.23.0
1.33.0
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
google.golang.org/protobuf@v1.26.0
1.33.0
1
hashicorp/waypoint:0.11.397d521a27498
google.golang.org/protobuf@v1.28.1
1.33.0
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
google.golang.org/protobuf@v1.24.0
1.33.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
google.golang.org/protobuf@v1.30.0
1.33.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
google.golang.org/protobuf@v1.28.1
1.33.0
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
google.golang.org/protobuf@v1.25.0
1.33.0
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
google.golang.org/protobuf@v1.28.1
1.33.0
1
hibiken/asynqmon:latestac80bcffd2f9
google.golang.org/protobuf@v1.30.0
1.33.0
1
hipages/php-fpm_exporter:2.2.09b5be9d3d955
google.golang.org/protobuf@v1.28.0
1.33.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
google.golang.org/protobuf@v1.27.1
1.33.0
1
holiman/nodemonitor:latest5cd609761065
google.golang.org/protobuf@v1.28.1
1.33.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
google.golang.org/protobuf@v1.31.0
1.33.0
1
huacnlee/gobackup:v3.1.1560be93229a5
google.golang.org/protobuf@v1.31.0
1.33.0
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
google.golang.org/protobuf@v1.28.1
1.33.0
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
google.golang.org/protobuf@v1.27.1
1.33.0
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/protobuf@v1.23.0
1.33.0
1
hyperledger/fabric-ca:1.5.0f270dfeee91d
google.golang.org/protobuf@v1.23.0
1.33.0
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
google.golang.org/protobuf@v1.27.1
1.33.0
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
google.golang.org/protobuf@v1.28.1
1.33.0
1
inaccel/cloud-init:latesta5d3d0af05c1
google.golang.org/protobuf@v1.32.0
1.33.0
1
inaccel/device-selector:latest44b4f274f40b
google.golang.org/protobuf@v1.31.0
1.33.0
1
inaccel/kubevirt-hack:latestbdfd61803a70
google.golang.org/protobuf@v1.32.0
1.33.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
google.golang.org/protobuf@v1.25.0
1.33.0
1
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/protobuf@v1.25.0
1.33.0
1
intel/multimodal-data-visualization:3.03426deb77337
google.golang.org/protobuf@v1.27.1
1.33.0
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
google.golang.org/protobuf@v1.28.1
1.33.0
1
invisibl/gravity-init:v1.0.91a970f84178b
google.golang.org/protobuf@v1.27.1
1.33.0
1
invisibl/identity-manager:1.0.01029f4fe20eb
google.golang.org/protobuf@v1.27.1
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.