StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,369
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

14,983
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

11,784
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,616
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

1,958
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,033

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
hashicorp/vault:1.14.0b2177a8bfe85
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
hashicorp/vault:1.8.4dfc3500beb0e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hashicorp/waypoint:0.11.397d521a27498
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
igrantio/bb-consent-api:2023.12.22d2ea6546ffe
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
inseefrlab/shelly:cloudshell31f04ca7436b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
intel/multimodal-data-visualization:3.03426deb77337
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
ipfs/go-ipfs:v0.13.117259397f587
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
ipfs/kubo:v0.17.0803fac58ba15
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
ipfs/kubo:v0.24.0e3de33bd746b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/operator:1.10.3655eefa11c84
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/operator:1.12.06cfce8a071b9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/operator:1.18.270f9d1fe5fff
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/pilot:1.16.0ac0284d75ec9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/pilot:1.17.1ce9d87606701
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
istio/pilot:1.15.2db08d6963975
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
istio/pilot:1.10.3e7e110a421c2
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/proxyv2:1.9.687a9db561d2e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/proxyv2:1.10.088c6c693e67a
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
istio/proxyv2:1.14.1df69c1a7af7c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
kubebb/cert-manager-controller:v1.8.020509de4b399
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubebuilder/kube-rbac-proxy:v0.16.03c4f708c6204
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubernetesui/dashboard:v2.6.1290bebc3cd96
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubernetesui/dashboard:v2.7.02e500d29e9d5
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubeshop/testkube-api-server:2.1.162e97dc620d9b4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kubevious/ui:1.2.16233e84bdd59
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
kusionstack/karpor:v0.6.4b707d3bf0abd
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
library/caddy:2.660fb54d36b4b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
library/caddy:2.2.0-alpine7367adca165f
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/caddy:2.4.5874405536b3e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/influxdb:2.8571eb4514977
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/influxdb:2.7.4-alpinea10d46445d68
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
library/influxdb:2.0.8ba10ac9ba17a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.