StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,937
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,232
irods-csi-drivercyverse0.12.03 of 4See more

irods-csi-driver cyverse 0.12.0

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/protobuf@v1.31.0
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,257
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,832
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,209
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,238
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,926
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,041
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,571
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

958
eg-edge-stackdatawire0.0.14 of 7See more

eg-edge-stack datawire 0.0.1

4 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
google.golang.org/protobuf@v1.31.0
1.33.0
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

15,781
eg-edge-stack-crdsdatawire0.0.11 of 2See more

eg-edge-stack-crds datawire 0.0.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,404
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

970
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,583
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,299
aws-service-quotas-exporterdeliveryheroVerified publisher0.1.41 of 1See more

aws-service-quotas-exporter deliveryhero 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

771
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,234
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

1,315
toxiproxydeliveryheroVerified publisher1.3.91 of 2See more

toxiproxy deliveryhero 1.3.9

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

598
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/protobuf@v1.28.0
1.33.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,722
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
google.golang.org/protobuf@v1.23.0
1.33.0
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.11 of 2See more

lxd8s devplayer0 0.5.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,431
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/protobuf@v1.26.0
1.33.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,507
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
google.golang.org/protobuf@v1.27.1
1.33.0
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
google.golang.org/protobuf@v1.31.0
1.33.0
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
google.golang.org/protobuf@v1.28.1
1.33.0
1
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
google.golang.org/protobuf@v1.28.1
1.33.0
1
owncloud/ocis:1.7.0d2efcae92c84
google.golang.org/protobuf@v1.26.0
1.33.0
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
google.golang.org/protobuf@v1.27.1
1.33.0
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
google.golang.org/protobuf@v1.21.0
1.33.0
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
google.golang.org/protobuf@v1.21.0
1.33.0
1
pannoi/kollektor:1.0.59559617788fc
google.golang.org/protobuf@v1.30.0
1.33.0
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
google.golang.org/protobuf@v1.21.0
1.33.0
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
google.golang.org/protobuf@v1.32.0
1.33.0
1
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/protobuf@v1.30.0
1.33.0
1
phntom/chartmuseum:v0.15.29242b4df9e65
google.golang.org/protobuf@v1.28.1
1.33.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
google.golang.org/protobuf@v1.28.0
1.33.0
1
phntom/goalert:0.0.298ca4df55499b
google.golang.org/protobuf@v1.31.0
1.33.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/protobuf@v1.31.0
1.33.0
1
phntom/mindav:0.1.7-kix35695f546abbb
google.golang.org/protobuf@v1.25.0
1.33.0
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
photoprism/photoprism:231128-ce284de9cc4f9c
google.golang.org/protobuf@v1.31.0
1.33.0
1
photoprism/photoprism:220629-jammy2954334adbda
google.golang.org/protobuf@v1.28.0
1.33.0
1
piblokto/backlokto-operator:v0.0.20963cda71e393
google.golang.org/protobuf@v1.30.0
1.33.0
1
pinclr/v2ray-proxy:latestf37f250b7091
google.golang.org/protobuf@v1.28.2-0.20220831092852-f930b1dc76e8
1.33.0
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
google.golang.org/protobuf@v1.21.0
1.33.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
google.golang.org/protobuf@v1.29.1
1.33.0
1
polyaxon/training-operator:2.1.0b5b29deaec9a
google.golang.org/protobuf@v1.30.0
1.33.0
1
pomerium/pomerium:v0.22.19c69b10a2126
google.golang.org/protobuf@v1.30.0
1.33.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
google.golang.org/protobuf@v1.28.1
1.33.0
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
google.golang.org/protobuf@v1.21.0
1.33.0
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
google.golang.org/protobuf@v1.28.0
1.33.0
1
prom/blackbox-exporter:v0.22.0608acee5704a
google.golang.org/protobuf@v1.27.1
1.33.0
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
google.golang.org/protobuf@v1.28.1
1.33.0
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
prom/influxdb-exporter:v0.11.427e33e18634a
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
prom/memcached-exporter:v0.9.001267317c95d
google.golang.org/protobuf@v1.23.0
1.33.0
1
prom/node-exporter:v1.6.0d2e48098c364
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/prometheus:v2.51.24f6c47e39a90
google.golang.org/protobuf@v1.32.0
1.33.0
1
prom/prometheus:v2.18.15880ec936055
google.golang.org/protobuf@v1.21.0
1.33.0
1
prom/prometheus:v2.48.0b440bc0e8aa5
google.golang.org/protobuf@v1.31.0
1.33.0
1
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/protobuf@v1.24.0
1.33.0
1
prom/prometheus:v2.22.2f7ffebdd428b
google.golang.org/protobuf@v1.24.0
1.33.0
1
prom/pushgateway:v1.5.128fe26c8b8b1
google.golang.org/protobuf@v1.28.1
1.33.0
1
prom/pushgateway:v1.4.33496e0f85943
google.golang.org/protobuf@v1.26.0
1.33.0
1
prom/snmp-exporter:v0.20.09d226d7de223
google.golang.org/protobuf@v1.23.0
1.33.0
1
prom/statsd-exporter:v0.24.061d866e93b56
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/statsd-exporter:v0.22.48be660470961
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
google.golang.org/protobuf@v1.25.0
1.33.0
1
qumine/ingress-controller:v0.8.5f2c8a2148381
google.golang.org/protobuf@v1.28.1
1.33.0
1
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/protobuf@v1.28.1
1.33.0
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
google.golang.org/protobuf@v1.26.0
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.