StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,369
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

14,983
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

11,784
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,616
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

1,958
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,033

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
owncloud/ocis:1.7.0d2efcae92c84
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
pomerium/pomerium:v0.22.19c69b10a2126
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
sarwansharma/minio:v359d1da9385d1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
semaphoreui/semaphore:v2.9.645b50bc11833f
github.com/go-jose/go-jose/v3@v3.0.2
3.0.3
1
semitechnologies/weaviate:1.19.17a00d226f063
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
sikalabs/slu:v0.72.07bd267f30247
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
slamdev/external-secrets-operator:0.0.8855f6625dda4
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
springhack/frpc_ingress:latest4aceb821da88
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
supabase/gotrue:v2.91.07174d551d720
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
surajwarbhe/grafana:v185248611e9f1
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/admin-tools:1.22.4258958fe2ff2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/admin-tools:1.22.0836af062af30
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/server:1.25.08a5798191dea
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/server:1.22.0ddeebf8bad8f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
temporalio/ui:2.30.25c2a3645d09c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
thmmniii/fbs-runner:v1.27.186105349c1a3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
thomseddon/traefik-forward-auth:269a2c985d2c5
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
traefik/mesh:v1.4.8cf071f3e165c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
treeverse/lakefs:0.69.0478f37a6cffc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
vikunja/api:0.17.18cba0520bf8c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
wener/frpc:v0.37.0cc9fd4da44c0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
wener/frps:v0.37.05c92cc9e8597
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/square/go-jose.v2@v2.0.0-20180411045311-89060dee6a84
no fix listed
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
gopkg.in/square/go-jose.v2@v2.0.0-20180411045311-89060dee6a84
no fix listed
1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
gcr.io/projectsigstore/cosigned784518ff3ee7
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.