StackRadar

CVE-2024-24789

Medium

Advisory

Published 4 Jun 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,258
of 17,821 indexed, latest versions
Container images
2,663
deployed by those charts
Fix available
1 of 2
affected packages

Mishandling of corrupt central directory record in archive/zip

Carried by container images the latest versions of 2,258 of 17,821 indexed charts deploy, on 2,663 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+129 more1.21.112,663
OSV records
DEBIAN-CVE-2024-24789GO-2024-2888
Also known as
BIT-golang-2024-24789

Charts affected

2,258 by stars
ChartLatestAffected imagesRadar Score
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
stdlib@go1.13.15
1.21.11

Open the chart page →

3,588
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.21.11

Open the chart page →

17,598
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
stdlib@go1.16.9
1.21.11

Open the chart page →

3,476
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
stdlib@go1.16.5
1.21.11

Open the chart page →

3,634
influxdb-exportergeek-cookbookVerified publisher1.2.21 of 1See more

influxdb-exporter geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.21.11

Open the chart page →

1,051
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.21.11

Open the chart page →

14,040
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
stdlib@go1.17.7
1.21.11

Open the chart page →

2,569
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
stdlib@go1.15.2
1.21.11

Open the chart page →

3,168
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
stdlib@go1.15.12
1.21.11

Open the chart page →

8,061
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.21.11

Open the chart page →

11,800
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.21.11

Open the chart page →

10,314
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.21.11

Open the chart page →

2,319
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.21.11

Open the chart page →

13,338
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.21.11

Open the chart page →

15,926
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
stdlib@go1.17.5
1.21.11

Open the chart page →

5,133
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.21.11

Open the chart page →

7,724
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
stdlib@go1.19.10
1.21.11
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.21.11

Open the chart page →

14,566
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.21.11

Open the chart page →

6,489
temporalglasskubeVerified publisher0.45.2-gk.19 of 14See more

temporal glasskube 0.45.2-gk.1

9 of the 14 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
stdlib@go1.21.10
1.21.11
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
stdlib@go1.22.3
1.21.11
temporalio/server:1.25.08a5798191dea
stdlib@go1.22.3
1.21.11
temporalio/ui:2.30.25c2a3645d09c
stdlib@go1.22.1
1.21.11
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.21.11
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.21.11
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.21.11
quay.io/prometheus/pushgateway:v1.8.0c159e946abf4
stdlib@go1.22.1
1.21.11
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.21.11

Open the chart page →

16,418
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
stdlib@go1.20.1
1.21.11
zhenghaoz/gorse-server:0.4.1239c565685b01
stdlib@go1.20.1
1.21.11
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
stdlib@go1.20.1
1.21.11

Open the chart page →

4,438
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.21.11

Open the chart page →

3,604
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
stdlib@go1.19.6
1.21.11

Open the chart page →

2,091
armada-operatorgresearch0.7.01 of 2See more

armada-operator gresearch 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
stdlib@go1.21.7
1.21.11

Open the chart page →

1,583
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
stdlib@go1.18
1.21.11
quay.io/groundcover/grafana:9.3.18c65b333a3d3
stdlib@go1.19.3
1.21.11
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
stdlib@go1.19.4
1.21.11

Open the chart page →

6,821
hawkhawk1.1.53 of 4See more

hawk hawk 1.1.5

3 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
stdlib@go1.17.9
1.21.11
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.21.11
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
stdlib@go1.20.11
1.21.11

Open the chart page →

13,679
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.21.11

Open the chart page →

8,568
uptime-kumahelmforgeVerified publisher1.5.131 of 1See more

uptime-kuma helmforge 1.5.13

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.21.11

Open the chart page →

30,728
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
stdlib@go1.19.6
1.21.11

Open the chart page →

4,251
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.21.11

Open the chart page →

6,990
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
stdlib@go1.20.4
1.21.11

Open the chart page →

16,517
hiverhiverVerified publisher0.1.459 of 10See more

hiver hiver 0.1.45

9 of the 10 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
hiversh/antigravity:0.1.45-microvm0e36d98402bc
stdlib@go1.19.8
1.21.11
hiversh/browser:0.1.45-microvmb5048c6342ce
stdlib@go1.19.8
1.21.11
hiversh/claude:0.1.45-microvm2fbf9f264498
stdlib@go1.19.8
1.21.11
hiversh/codex:0.1.45-microvm4f43130f51e5
stdlib@go1.19.8
1.21.11
hiversh/controller:0.1.45b0b85f8942c7
stdlib@go1.19.8
1.21.11
hiversh/copilot:0.1.45-microvm50c07b84f298
stdlib@go1.19.8
1.21.11
hiversh/node:0.1.45-alpine-microvm836a37641941
stdlib@go1.19.8
1.21.11
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
stdlib@go1.19.8
1.21.11
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
stdlib@go1.19.8
1.21.11

Open the chart page →

21,549
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.21.11

Open the chart page →

2,921
holoinsightholoinsight0.2.51 of 6See more

holoinsight holoinsight 0.2.5

1 of the 6 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
holoinsight/otelcontribcol:latest42ba8dc3113c
stdlib@go1.19
1.21.11

Open the chart page →

27,901
holoinsight-agentholoinsight0.2.51 of 2See more

holoinsight-agent holoinsight 0.2.5

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
holoinsight/agent:latest5c3994e742f8
stdlib@go1.22.1
1.21.11

Open the chart page →

1,804
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.21.11

Open the chart page →

6,818
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
stdlib@go1.17.2
1.21.11

Open the chart page →

1,580
spoolmanideaplexusVerified publisher2.7.11 of 1See more

spoolman ideaplexus 2.7.1

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.21.11

Open the chart page →

1,772
ilum-coreilumOfficialVerified publisher6.7.31 of 5See more

ilum-core ilum 6.7.3

1 of the 5 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ilum/mongodb:6.0.542b6d774c37d
stdlib@go1.20.12
1.21.11

Open the chart page →

3,561
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.21.11

Open the chart page →

15,704
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
stdlib@go1.17.1
1.21.11

Open the chart page →

2,168
telegraf-operatorinfluxdata1.4.01 of 1See more

telegraf-operator influxdata 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
stdlib@go1.18.10
1.21.11

Open the chart page →

925
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
stdlib@go1.16.6
1.21.11

Open the chart page →

74,823
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.21.11

Open the chart page →

74,898
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.21.11

Open the chart page →

74,843
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.21.11

Open the chart page →

74,843
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.21.11

Open the chart page →

75,124
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.21.11

Open the chart page →

1,820
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
stdlib@go1.20.14
1.21.11

Open the chart page →

1,142
statpingitscontainedVerified publisher0.1.91 of 1See more

statping itscontained 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
statping/statping:v0.90.6532f26fffca46
stdlib@go1.14.8
1.21.11

Open the chart page →

3,538
traefik-forward-authitscontainedVerified publisher1.0.21 of 1See more

traefik-forward-auth itscontained 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-24789.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.21.11

Open the chart page →

2,235

Container images carrying it

2,663 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.21.11
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.21.11
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.21.11
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.21.11
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.21.11
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.21.11
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.21.11
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.21.11
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.21.11
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.21.11
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.21.11
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.11
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.21.11
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.