StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,369
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

14,983
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

11,784
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,616
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

1,958
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,033

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
1password/connect-api:1.7.26aa94cf713f9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
1password/connect-sync:1.7.2fe527ed9d81f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
akeyless/gateway:5.3.13d2e7dce5eb9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alex6021710/ai-scale-saver:latestf73e8d60fd03
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alpine/k8s:1.22.600ac10bcb759
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
alpine/k8s:1.27.321b24e6bf801
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
alpine/k8s:1.18.16a41efe02a041
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
alpine/k8s:1.28.2fc059f056ad0
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
anchore/anchore-engine:v0.10.0bde9eedf639d
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bicarus/wg-access-server:v0.8.206cab48e9334
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:v1.224.066f836ef778b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:v1.753.0770ad9ec3190
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:3.62.17729da148c61
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
casbin/casdoor:3.62.0e08231f16c00
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
chaosnative/cle-auth-server:2.7.072ee352bc333
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
chirpstack/chirpstack-application-server:3fb7667fe037f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
cloudflare/cloudflared:2023.10.0c18744ae1767
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
cockroachdb/cockroach-operator:v2.1.0983312754620
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
coderenvs/coder-service:1.44.61deffc4670e6
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
containous/maesh:v1.3.2587162516502
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.08eb7a26605c9
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
craftypath/sops-operator:v0.8.0402a0024c732
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/square/go-jose.v2@v2.4.0
no fix listed
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.