StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,937
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,232
irods-csi-drivercyverse0.12.03 of 4See more

irods-csi-driver cyverse 0.12.0

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/protobuf@v1.31.0
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,257
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,832
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,209
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,238
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,926
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,041
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,571
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

958
eg-edge-stackdatawire0.0.14 of 7See more

eg-edge-stack datawire 0.0.1

4 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
google.golang.org/protobuf@v1.31.0
1.33.0
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

15,781
eg-edge-stack-crdsdatawire0.0.11 of 2See more

eg-edge-stack-crds datawire 0.0.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,404
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

970
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,583
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,299
aws-service-quotas-exporterdeliveryheroVerified publisher0.1.41 of 1See more

aws-service-quotas-exporter deliveryhero 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

771
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,234
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

1,315
toxiproxydeliveryheroVerified publisher1.3.91 of 2See more

toxiproxy deliveryhero 1.3.9

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

598
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/protobuf@v1.28.0
1.33.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,722
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
google.golang.org/protobuf@v1.23.0
1.33.0
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.11 of 2See more

lxd8s devplayer0 0.5.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,431
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/protobuf@v1.26.0
1.33.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,507
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
jhonbrownn/elchi-discovery:latest8f6551ecc98c
google.golang.org/protobuf@v1.30.0
1.33.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
google.golang.org/protobuf@v1.28.0
1.33.0
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
google.golang.org/protobuf@v1.23.0
1.33.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
google.golang.org/protobuf@v1.30.0
1.33.0
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
google.golang.org/protobuf@v1.30.0
1.33.0
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
google.golang.org/protobuf@v1.30.0
1.33.0
1
junktext/getting-started:1.0.5a70936c04aed
google.golang.org/protobuf@v1.28.1
1.33.0
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
google.golang.org/protobuf@v1.27.1
1.33.0
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
google.golang.org/protobuf@v1.25.0
1.33.0
1
kaiso/kom-operator:v2.2.0e0e22b928bdd
google.golang.org/protobuf@v1.31.0
1.33.0
1
keptncontrib/prometheus-service:0.6.029969dd547de
google.golang.org/protobuf@v1.21.0
1.33.0
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
google.golang.org/protobuf@v1.26.0
1.33.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
google.golang.org/protobuf@v1.30.0
1.33.0
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
google.golang.org/protobuf@v1.25.0
1.33.0
1
kiosksh/kiosk:0.2.11501725ba2025
google.golang.org/protobuf@v1.25.0
1.33.0
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
google.golang.org/protobuf@v1.27.1
1.33.0
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
google.golang.org/protobuf@v1.27.1
1.33.0
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
google.golang.org/protobuf@v1.27.1
1.33.0
1
kserve/kserve-controller:v0.10.022ff858b57c1
google.golang.org/protobuf@v1.28.1
1.33.0
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
google.golang.org/protobuf@v1.26.0
1.33.0
1
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubebb/cert-manager-controller:v1.8.020509de4b399
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubebb/core:v0.1.62b9e7f451d6b
google.golang.org/protobuf@v1.28.1
1.33.0
1
kubebb/core:lateste366c34a9b8d
google.golang.org/protobuf@v1.32.0
1.33.0
1
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
google.golang.org/protobuf@v1.28.0
1.33.0
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
google.golang.org/protobuf@v1.28.0
1.33.0
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
google.golang.org/protobuf@v1.28.0
1.33.0
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
google.golang.org/protobuf@v1.26.0
1.33.0
1
kubebb/mesh-operator:v5.7.0163ebbfc7a82
google.golang.org/protobuf@v1.28.1
1.33.0
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
google.golang.org/protobuf@v1.28.0
1.33.0
1
kubebb/resource-viewer:v0.2.065bb40b353db
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
google.golang.org/protobuf@v1.31.0
1.33.0
1
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
google.golang.org/protobuf@v1.25.0
1.33.0
1
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
google.golang.org/protobuf@v1.26.0
1.33.0
1
kubedb/operator:v0.24.01a06ff0bda52
google.golang.org/protobuf@v1.25.0
1.33.0
1
kubeedge/edgemesh-agent:latest460c6061b608
google.golang.org/protobuf@v1.30.0
1.33.0
1
kubeedge/edgemesh-server:latesta437cf5ec0ae
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
google.golang.org/protobuf@v1.25.0
1.33.0
1
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
google.golang.org/protobuf@v1.25.0
1.33.0
1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
google.golang.org/protobuf@v1.25.0
1.33.0
1
kubeflownotebookswg/kfam:v1.9.22060a2ede788
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
google.golang.org/protobuf@v1.30.0
1.33.0
1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
google.golang.org/protobuf@v1.27.1
1.33.0
1
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
google.golang.org/protobuf@v1.27.1
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.