StackRadar

CVE-2024-28180

Medium

Advisory

Published 7 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
413
of 17,781 indexed, latest versions
Container images
395
deployed by those charts
Fix available
3 of 4
affected packages

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Carried by container images the latest versions of 413 of 17,781 indexed charts deploy, on 395 images.

Affected packageAffected versionsFixed inImages
gopkg.in/square/go-jose.v2golangv2.0.0-20180411045311-89060dee6a84, v2.2.2, v2.3.0, v2.3.1+5 moreno fix listed353
github.com/go-jose/go-jose/v3golangv3.0.0, v3.0.1, v3.0.1-0.20221117193127-916db76e8214, v3.0.23.0.368
gopkg.in/go-jose/go-jose.v2golangv2.6.12.6.33
libgpg-errorrpm1.29-1.81.29-150000.3.3.11
OSV records
GHSA-c5q2-7r4c-mv6gSUSE-SU-2024:2754-1
Also known as
GO-2024-2631

Charts affected

413 by stars
ChartLatestAffected imagesRadar Score
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

6,915
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

3,369
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/go-jose/go-jose/v3@v3.0.1
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

14,983
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

11,784
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

2,616
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed

Open the chart page →

1,958
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2024-28180.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed

Open the chart page →

5,033

Container images carrying it

395 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
6
quay.io/devtron/kubectl:latest2ad610626658
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
6
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
4
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
3
caddy/ingress:v0.2.118d1366fc0e9
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
3
grafana/grafana:8.2.500568d89c4f8
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
3
oryd/hydra:v2.2.02c93beb5e5f2
github.com/go-jose/go-jose/v3@v3.0.1
3.0.3
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
3
quay.io/devtron/clair:4.3.675fb847ac045
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
3
1password/scim:v2.3.129d0c6cb67eb
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
cs3org/revad:v1.19.03b57a34a7dfd
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
cs3org/revad:v1.24.0e80a4d67b352
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
datawire/aes:1.14.48588eafe6862
gopkg.in/square/go-jose.v2@v2.3.1
no fix listed
2
governify/dashboard:lateste83a17ba5038
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
grafana/grafana:9.2.4057896e23443
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
grafana/grafana:7.3.5511bc20bfcd1
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
2
hashicorp/consul:1.14.2e38576edcdfd
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
hashicorp/vault:1.8.34db614d40d0e
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
hashicorp/vault:1.15.26b4e5dadf082
github.com/go-jose/go-jose/v3@v3.0.0
gopkg.in/square/go-jose.v2@v2.6.0
3.0.3
no fix listed
2
hashicorp/vault:1.12.18de4d5f31b38
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
istio/proxyv2:1.18.0757d28c24100
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
istio/proxyv2:1.10.3a78b7a165744
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
kubernetesui/dashboard:v2.2.0148991563e37
gopkg.in/square/go-jose.v2@v2.4.1
no fix listed
2
library/influxdb:2.6.1-alpine44a366dd7724
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
library/influxdb:2.7b8d940ca9376
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
library/traefik:v2.57d5a6ae66572
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
oryd/kratos:v1.0.0d06fc5845f63
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
place1/wg-access-server:v0.4.62b2f3ea80ed6
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
rancher/k3s:v1.26.0-k3s19380f5dbae9a
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
statping/statping:v0.90.74e874da513a5c
gopkg.in/square/go-jose.v2@v2.5.0
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/go-jose/go-jose/v3@v3.0.0
3.0.3
2
temporalio/server:1.22.4c0a44c26397b
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
temporalio/ui:2.16.2af9c9349708f
gopkg.in/square/go-jose.v2@v2.6.0
no fix listed
2
xelalex/dregsy:0.4.3574054e1c417
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
gopkg.in/square/go-jose.v2@v2.2.2
no fix listed
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
gopkg.in/square/go-jose.v2@v2.5.1
no fix listed
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.