CVE-2024-28835
MediumAdvisory
Published 21 Mar 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.0
- base score, highest
- EPSS
- 0.004
- 32nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 322
- of 17,781 indexed, latest versions
- Container images
- 309
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 322 of 17,781 indexed charts deploy, on 309 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gnutls28deb | 3.7.3-4ubuntu1, 3.7.3-4ubuntu1.1, 3.7.3-4ubuntu1.2, 3.7.3-4ubuntu1.3+4 more | 3.7.3-4ubuntu1.5, 3.7.9-2+deb12u3 | 294 |
| gnutlsapk | 3.8.0-r2, 3.8.3-r0 | 3.8.4-r0 | 15 |
- OSV records
- ALPINE-CVE-2024-28835DEBIAN-CVE-2024-28835UBUNTU-CVE-2024-28835
- Also known as
- USN-6733-1
Charts affected
322 by stars
Container images carrying it
309 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 70fd7c00418d | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | 578934444f04 | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | 5b6701d8fb31 | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | acaf37352569 | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | 351d6685dc6f | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | 60950ef63764 | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | 93889c3d8a34 | gnutls28 | 3.7.3-4ubuntu1.5 | 1 |
| quay.io/ | e0d9b93dbf2b | gnutls28 | 3.7.9-2+deb12u3 | 1 |
| registry.k8s.io/ | fd9722fd02e3 | gnutls28 | 3.7.9-2+deb12u3 | 1 |