StackRadar

CVE-2024-24789

Medium

Advisory

Published 4 Jun 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,258
of 17,821 indexed, latest versions
Container images
2,663
deployed by those charts
Fix available
1 of 2
affected packages

Mishandling of corrupt central directory record in archive/zip

Carried by container images the latest versions of 2,258 of 17,821 indexed charts deploy, on 2,663 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+129 more1.21.112,663
OSV records
DEBIAN-CVE-2024-24789GO-2024-2888
Also known as
BIT-golang-2024-24789

Charts affected

2,258 by stars
ChartLatestAffected imagesRadar Score
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.21.11

Open the chart page →

69,141
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
stdlib@go1.21.4
1.21.11

Open the chart page →

1,901
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
stdlib@go1.19.9
1.21.11

Open the chart page →

1,705
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
stdlib@go1.17.11
1.21.11
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
stdlib@go1.17.11
1.21.11
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
stdlib@go1.17.11
1.21.11
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
stdlib@go1.17.11
1.21.11

Open the chart page →

7,801
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.21.11

Open the chart page →

1,818
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
stdlib@go1.22.3
1.21.11

Open the chart page →

791
ghostcloudpirates-ghostVerified publisher0.20.251 of 3See more

ghost cloudpirates-ghost 0.20.25

1 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.21.11

Open the chart page →

7,020
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
stdlib@go1.18
1.21.11

Open the chart page →

1,708
coder-observabilitycoder-observabilityVerified publisher0.7.311 of 21See more

coder-observability coder-observability 0.7.3

11 of the 21 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
stdlib@go1.22.1
1.21.11
grafana/loki:3.1.0d947e68a84d9
stdlib@go1.22.2
1.21.11
grafana/loki-canary:3.1.039baf6d67f85
stdlib@go1.22.2
1.21.11
prom/memcached-exporter:v0.14.2d8a61419b841
stdlib@go1.21.5
1.21.11
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.21.11
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
stdlib@go1.18.6
1.21.11
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
stdlib@go1.18.6
1.21.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.21.11
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.21.11
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.21.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.21.11

Open the chart page →

24,973
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
stdlib@go1.21.5
1.21.11

Open the chart page →

17,018
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
stdlib@go1.16.6
1.21.11

Open the chart page →

3,089
cosmocosmo-platformOfficialVerified publisher0.20.03 of 10See more

cosmo cosmo-platform 0.20.0

3 of the 10 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.21.11
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stdlib@go1.22.3
1.21.11
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.21.11

Open the chart page →

29,756
deepflowdeepflow6.2.2015 of 8See more

deepflow deepflow 6.2.201

5 of the 8 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.21.11
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
stdlib@go1.19.3
1.21.11
deepflowce/deepflow-server:v6.2.21477e7334d13
stdlib@go1.18.10
1.21.11
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.21.11
grafana/grafana:9.3.6e5a9655dabef
stdlib@go1.19.4
1.21.11

Open the chart page →

16,009
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
stdlib@go1.21.10
1.21.11

Open the chart page →

3,482
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
stdlib@go1.21.7
1.21.11

Open the chart page →

1,624
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
stdlib@go1.17.6
1.21.11

Open the chart page →

2,538
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.21.11

Open the chart page →

1,277
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.21.11

Open the chart page →

2,273
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.21.11

Open the chart page →

12,064
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.21.11

Open the chart page →

14,568
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.21.11

Open the chart page →

13,897
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.21.11

Open the chart page →

5,325
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
stdlib@go1.17.7
1.21.11

Open the chart page →

3,036
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.21.11

Open the chart page →

1,111
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
stdlib@go1.15.10
1.21.11

Open the chart page →

1,746
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
stdlib@go1.17.10
1.21.11

Open the chart page →

7,637
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.21.11
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.21.11

Open the chart page →

4,768
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.21.11

Open the chart page →

9,851
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
stdlib@go1.17.8
1.21.11

Open the chart page →

10,296
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.21.11

Open the chart page →

2,338
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
stdlib@go1.14.13
1.21.11

Open the chart page →

3,379
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
stdlib@go1.17
1.21.11

Open the chart page →

2,612
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.21.11

Open the chart page →

10,867
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.21.11

Open the chart page →

2,235
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.21.11

Open the chart page →

11,978
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.21.11

Open the chart page →

6,711
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
stdlib@go1.13.7
1.21.11

Open the chart page →

1,655
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
stdlib@go1.17.2
1.21.11

Open the chart page →

1,559
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
stdlib@go1.19.5
1.21.11

Open the chart page →

2,624
coreinstill-aiOfficialVerified publisher0.1.753 of 15See more

core instill-ai 0.1.75

3 of the 15 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.21.11
library/influxdb:2.3.0-alpined7f5dd5f70e2
stdlib@go1.18.3
1.21.11
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.21.11

Open the chart page →

30,858
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
stdlib@go1.15.6
1.21.11

Open the chart page →

2,212
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.21.11

Open the chart page →

4,593
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.21.11

Open the chart page →

7,554
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.21.11

Open the chart page →

1,607
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.21.11

Open the chart page →

2,314
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
stdlib@go1.21.3
1.21.11

Open the chart page →

1,566
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
stdlib@go1.19.6
1.21.11

Open the chart page →

1,621
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
stdlib@go1.13.3
1.21.11
apache/skywalking-ui:8.1.067d50e4deff4
stdlib@go1.13.3
1.21.11

Open the chart page →

18,058
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
stdlib@go1.19.1
1.21.11
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.21.11
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.21.11

Open the chart page →

14,254
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.04 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

4 of the 6 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.21.11
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.21.11
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.21.11
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.21.11

Open the chart page →

59,093

Container images carrying it

2,663 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.21.11
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.21.11
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.21.11
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.21.11
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.21.11
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.21.11
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.21.11
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.21.11
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.21.11
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.21.11
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.21.11
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.21.11
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.