StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,369
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

14,983
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

11,784
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,616
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

1,958
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,033

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
datawire/aes:1.13.62beb65062c8b
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
datawire/aes:3.11.195ec30b3c732
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
defactops/defactops-ui:1.0.16825cdf9ba706
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
devopsfaith/krakend:2.6.34c678c224f67
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
devopsfaith/krakend:2.7.09219cda867e2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
dexidp/dex:v2.39.1-distroless43655afd1a8f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
dollarshaveclub/furan2:master14a257836529
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
dragonflyoss/scheduler:v2.1.49523785c77787
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
gopkg.in/square/go-jose.v2@v2.3.0
no fix listed
1
epamedp/edp-headlamp:0.25.093417e18bb1a
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
filebrowser/filebrowser:v2.18.04fcd47af573c
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
flomesh/osm-edge-injector:1.3.947287e3ad324
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
goalert/goalert:v0.32.008d57388b0cb
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
goharbor/harbor-core:v2.9.06412d679fdc3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
goharbor/harbor-core:v2.5.386bf3031f4a7
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/agent:v0.40.3f6cbec9409be
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
grafana/grafana:6.6.0052147d7e0ec
gopkg.in/square/go-jose.v2@v2.3.0
no fix listed
1
grafana/grafana:10.1.50679e877ba20
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
grafana/grafana:7.5.609bb407e26ab
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:7.3.315b977f5207d
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
grafana/grafana:9.4.71a359d92f40e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
grafana/grafana:9.5.239c849cebccc
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
grafana/grafana:8.0.3696823fbc561
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:10.2.36b5b37eb35bb
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
grafana/grafana:7.3.46d42886b3ebe
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
grafana/grafana:7.2.1733842cca5bd
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
grafana/grafana:9.4.376dcf36e7d2a
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:10.3.38640e5038e83
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
grafana/grafana:9.1.19746858c20e6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:9.0.1a738d0744784
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:6.5.1befcd84da2c1
gopkg.in/square/go-jose.v2@v2.3.0
no fix listed
1
grafana/grafana:8.3.5cd7cb4345aa7
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:8.3.4cf81d2c753c8
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:7.4.5d322192ed2fa
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:8.5.3ecc1b80b8ca2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
grafana/grafana:10.4.0f9811e4e687f
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
hashicorp/boundary:0.8.1fb70bd9210ff
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/consul:1.17.0712fe02d2f84
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.