StackRadar

CVE-2024-24789

Medium

Advisory

Published 4 Jun 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,249
of 17,813 indexed, latest versions
Container images
2,652
deployed by those charts
Fix available
1 of 2
affected packages

Mishandling of corrupt central directory record in archive/zip

Carried by container images the latest versions of 2,249 of 17,813 indexed charts deploy, on 2,652 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+129 more1.21.112,652
OSV records
DEBIAN-CVE-2024-24789GO-2024-2888
Also known as
BIT-golang-2024-24789

Charts affected

2,249 by stars
ChartLatestAffected imagesRadar Score
castai-tetragoncastaiVerified publisher0.6.12 of 4See more

castai-tetragon castai 0.6.1

2 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
stdlib@go1.19.2
1.21.11
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
stdlib@go1.18.3
1.21.11

Open the chart page →

4,145
castware-componentscastaiVerified publisher0.4.01 of 1See more

castware-components castai 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
stdlib@go1.19.3
1.21.11

Open the chart page →

3,452
temporalcastaiVerified publisher0.54.27 of 14See more

temporal castai 0.54.2

7 of the 14 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.21.11
temporalio/ui:2.33.05c586a3c8ec5
stdlib@go1.22.1
1.21.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.21.11
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.21.11
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.21.11
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.21.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.21.11

Open the chart page →

16,271
catalyst-agentscatalyst-agents0.1.335 of 18See more

catalyst-agents catalyst-agents 0.1.33

5 of the 18 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
stdlib@go1.20.5
1.21.11
grafana/loki:3.0.0757b5fadf816
stdlib@go1.21.9
1.21.11
grafana/loki-canary:3.0.028d7c00588aa
stdlib@go1.21.9
1.21.11
grafana/tempo:2.5.0f0200a9bff6d
stdlib@go1.21.3
1.21.11
prom/memcached-exporter:v0.14.2d8a61419b841
stdlib@go1.21.5
1.21.11

Open the chart page →

17,686
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
stdlib@go1.14.10
1.21.11

Open the chart page →

6,391
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.21.11

Open the chart page →

6,222
openldap_exporterccowleyVerified publisher0.1.01 of 1See more

openldap_exporter ccowley 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.21.11

Open the chart page →

2,144
cert-manager-webhook-civocert-manager-webhook-civoVerified publisher0.0.0-05b683cb6efdc99135f68af18007954e74f184041 of 1See more

cert-manager-webhook-civo cert-manager-webhook-civo 0.0.0-05b683cb6efdc99135f68af18007954e74f18404

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
okteto/civo-webhook:0.5.357cd51176538
stdlib@go1.21.3
1.21.11

Open the chart page →

1,286
cert-manager-webhook-infoblox-wapicert-manager-webhook-infoblox-wapiVerified publisher1.5.21 of 1See more

cert-manager-webhook-infoblox-wapi cert-manager-webhook-infoblox-wapi 1.5.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
stdlib@go1.16.15
1.21.11

Open the chart page →

2,353
cert-manager-webhook-namecheapcert-manager-webhook-namecheap0.1.21 of 1See more

cert-manager-webhook-namecheap cert-manager-webhook-namecheap 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
stdlib@go1.20.6
1.21.11

Open the chart page →

1,767
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
stdlib@go1.19.13
1.21.11
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.21.11

Open the chart page →

7,785
clechaosnative0.2.73 of 6See more

cle chaosnative 0.2.7

3 of the 6 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
chaosnative/cle-auth-server:2.7.072ee352bc333
stdlib@go1.16.15
1.21.11
chaosnative/cle-license-module:2.7.062cf6adc355e
stdlib@go1.16.15
1.21.11
chaosnative/cle-server:2.7.0e7bcff4a20c0
stdlib@go1.16.15
1.21.11

Open the chart page →

16,435
calibre-webcharts-derwitt-devVerified publisher1.1.21 of 1See more

calibre-web charts-derwitt-dev 1.1.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
stdlib@go1.17.8
1.21.11

Open the chart page →

5,079
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
stdlib@go1.20.12
1.21.11

Open the chart page →

2,126
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.21.11

Open the chart page →

8,419
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
stdlib@go1.13.11
1.21.11

Open the chart page →

2,877
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
stdlib@go1.13.11
1.21.11

Open the chart page →

2,829
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
stdlib@go1.20.4
1.21.11

Open the chart page →

1,440
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
stdlib@go1.19.4
1.21.11
countly/frontend:25.05.42acbc11499b6
stdlib@go1.19.4
1.21.11

Open the chart page →

7,325
dnsbl-exporterchristianhuthVerified publisher1.4.01 of 2See more

dnsbl-exporter christianhuth 1.4.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/luzilla/dnsbl_exporter:v0.7.0-rc3d9767232a55e
stdlib@go1.20.14
1.21.11

Open the chart page →

1,460
kubedoomchristianhuthVerified publisher1.1.21 of 1See more

kubedoom christianhuth 1.1.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/storax/kubedoom:0.6.0851ba8c80b93
stdlib@go1.17.6
1.21.11

Open the chart page →

1,021
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
stdlib@go1.16.15
1.21.11

Open the chart page →

2,291
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
stdlib@go1.19.10
1.21.11

Open the chart page →

1,942
sith-exporterschronicleVerified publisher0.2.41 of 1See more

sith-exporters chronicle 0.2.4

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
stdlib@go1.19.13
1.21.11

Open the chart page →

997
tor-proxychronicleVerified publisher0.1.01 of 1See more

tor-proxy chronicle 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.21.11

Open the chart page →

3,384
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.21.11

Open the chart page →

3,603
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
stdlib@go1.17.3
1.21.11

Open the chart page →

3,468
capi-kamaji-vsphere-fullclastixVerified publisher1.0.11 of 9See more

capi-kamaji-vsphere-full clastix 1.0.1

1 of the 9 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
stdlib@go1.21.5
1.21.11

Open the chart page →

6,012
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
stdlib@go1.19.2
1.21.11
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
stdlib@go1.19.5
1.21.11
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
stdlib@go1.19.5
1.21.11
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
stdlib@go1.19.5
1.21.11
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
stdlib@go1.19.5
1.21.11

Open the chart page →

7,142
kamajiclastixVerified publisher0.0.0+latest1 of 4See more

kamaji clastix 0.0.0+latest

1 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/coreos/etcd:v3.5.628cb0630cb85
stdlib@go1.16.15
1.21.11

Open the chart page →

4,669
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
stdlib@go1.22.2
1.21.11

Open the chart page →

2,765
kamaji-etcdclastixVerified publisher0.18.02 of 4See more

kamaji-etcd clastix 0.18.0

2 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
cfssl/cfssl:latestc9018c2ddf0b
stdlib@go1.20.14
1.21.11
quay.io/coreos/etcd:v3.5.628cb0630cb85
stdlib@go1.16.15
1.21.11

Open the chart page →

12,123
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
stdlib@go1.16
1.21.11
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
stdlib@go1.16
1.21.11
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.21.11
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
stdlib@go1.17.3
1.21.11

Open the chart page →

7,417
kube-acp-stackcloudentity2.28.02 of 7See more

kube-acp-stack cloudentity 2.28.0

2 of the 7 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
stdlib@go1.18.1
1.21.11
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
stdlib@go1.13.14
1.21.11

Open the chart page →

21,162
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
stdlib@go1.15.14
1.21.11
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
stdlib@go1.15.14
1.21.11
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
stdlib@go1.15.2
1.21.11
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
stdlib@go1.16.6
1.21.11
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
stdlib@go1.15.2
1.21.11
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
stdlib@go1.15.2
1.21.11

Open the chart page →

18,046
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
stdlib@go1.19.10
1.21.11

Open the chart page →

25,525
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
stdlib@go1.17.5
1.21.11

Open the chart page →

6,706
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
stdlib@go1.18.1
1.21.11

Open the chart page →

6,932
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.21.11

Open the chart page →

2,819
robot-shopcloud-native-toolkit1.1.12 of 12See more

robot-shop cloud-native-toolkit 1.1.1

2 of the 12 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.21.11
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.21.11

Open the chart page →

29,653
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
stdlib@go1.20.12
1.21.11
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
stdlib@go1.19.1
1.21.11

Open the chart page →

18,471
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
stdlib@go1.16.13
1.21.11

Open the chart page →

3,144
galaxycloudve6.8.81 of 3See more

galaxy cloudve 6.8.8

1 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
tusproject/tusd:v1.13.0f8088058b80f
stdlib@go1.21.0
1.21.11

Open the chart page →

5,650
galaxy-cvmfs-csicloudve2.5.12 of 3See more

galaxy-cvmfs-csi cloudve 2.5.1

2 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.21.11
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
stdlib@go1.21.5
1.21.11

Open the chart page →

1,515
galaxy-depscloudve1.1.14 of 7See more

galaxy-deps cloudve 1.1.1

4 of the 7 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
stdlib@go1.17
1.21.11
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
stdlib@go1.17
1.21.11
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
stdlib@go1.20.3
1.21.11
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.21.11

Open the chart page →

10,636
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
stdlib@go1.17.13
1.21.11
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
stdlib@go1.20.3
1.21.11
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.21.11
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
stdlib@go1.16.2
1.21.11

Open the chart page →

16,207
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.21.11

Open the chart page →

81,044
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
stdlib@go1.17.10
1.21.11

Open the chart page →

2,069
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.21.11

Open the chart page →

2,854
metaflowcluster-deploy0.2.21 of 1See more

metaflow cluster-deploy 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
stdlib@go1.20.2
1.21.11

Open the chart page →

8,201

Container images carrying it

2,652 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.21.11
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.