StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
412
of 17,787 indexed, latest versions
Container images
394
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 412 of 17,787 indexed charts deploy, on 394 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed352
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

412 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,369
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

14,983
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

11,784
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,616
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

1,958
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,033

Container images carrying it

394 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
quay.io/brancz/kube-rbac-proxy:v0.15.02c7b120590cb
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/brancz/kube-rbac-proxy:v0.18.0754ab2a723c8
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
1
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/minio/minio:RELEASE.2024-06-04T19-20-08Zc6b68f158628
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
1
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/go-jose/go-jose.v2@v2.6.1
3.0.3
2.6.3
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
1
quay.io/seamware/did-helper:0.6.0799c5f566952
github.com/go-jose/go-jose/v3@v3.0.1-0.20221117193127-916db76e8214
3.0.3
1
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/go-jose/go-jose.v2@v2.6.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
2.6.3
no fix listed
1
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.