StackRadar

CVE-2024-29018

High

Advisory

Published 20 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
290
of 17,781 indexed, latest versions
Container images
262
deployed by those charts
Fix available
1 of 2
affected packages

Moby's external DNS requests from 'internal' networks could lead to data exfiltration

Carried by container images the latest versions of 290 of 17,781 indexed charts deploy, on 262 images.

Affected packageAffected versionsFixed inImages
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6no fix listed1
github.com/docker/dockergolangv0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+41 more23.0.11, 25.0.5261
OSV records
DEBIAN-CVE-2024-29018GHSA-mq39-4gv4-mvpx
Also known as
GO-2024-2659

Charts affected

290 by stars
ChartLatestAffected imagesRadar Score
catalyst-agentscatalyst-agents0.1.301 of 18See more

catalyst-agents catalyst-agents 0.1.30

1 of the 18 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

15,027
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

8,408
capsule-rancher-addonclastixVerified publisher0.1.11 of 5See more

capsule-rancher-addon clastix 0.1.1

1 of the 5 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

7,104
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/docker/docker@v20.10.3+incompatible
23.0.11

Open the chart page →

25,151
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/docker/docker@v1.4.2-0.20191121165722-d1d5f6476656
23.0.11

Open the chart page →

6,695
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/docker/docker@v20.10.3+incompatible
23.0.11

Open the chart page →

6,921
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

16,069
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

19,338
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

12,907
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

8,408
cosmo-traefikcosmoVerified publisher0.9.11 of 2See more

cosmo-traefik cosmo 0.9.1

1 of the 2 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
library/traefik:v2.10.11489caffaedb
github.com/docker/docker@v20.10.21+incompatible
23.0.11

Open the chart page →

3,672
katibcowboysysopVerified publisher2.4.21 of 4See more

katib cowboysysop 2.4.2

1 of the 4 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
github.com/docker/docker@v1.4.2-0.20190924003213-a8608b5b67c7
23.0.11

Open the chart page →

6,542
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
github.com/docker/docker@v17.12.0-ce-rc1.0.20200309214505-aa6a9891b09c+incompatible
23.0.11

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
github.com/docker/docker@v17.12.0-ce-rc1.0.20200309214505-aa6a9891b09c+incompatible
23.0.11

Open the chart page →

5,973
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
github.com/docker/docker@v20.10.21+incompatible
23.0.11

Open the chart page →

15,380
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
github.com/docker/docker@v20.10.7+incompatible
23.0.11

Open the chart page →

3,238
cloudwatch-agent-prometheusdasmeta0.2.21 of 1See more

cloudwatch-agent-prometheus dasmeta 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
github.com/docker/docker@v1.13.1
23.0.11

Open the chart page →

2,977
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
github.com/docker/docker@v23.0.1+incompatible
23.0.11

Open the chart page →

1,926
agent-helmdatasaker0.1.81 of 6See more

agent-helm datasaker 0.1.8

1 of the 6 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

7,571
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/docker/docker@v20.10.12+incompatible
23.0.11
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/docker/docker@v20.10.12+incompatible
23.0.11

Open the chart page →

4,722
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/docker/docker@v0.7.3-0.20190327010347-be7ac8be2ae0
23.0.11

Open the chart page →

10,466
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

12,949
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

1,580
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

68,240
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/docker/docker@v20.10.7+incompatible
23.0.11

Open the chart page →

2,435
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/docker/docker@v0.7.3-0.20190327010347-be7ac8be2ae0
23.0.11

Open the chart page →

10,466
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

12,949
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

1,580
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
github.com/docker/docker@v20.10.7+incompatible
23.0.11

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
23.0.11

Open the chart page →

32,902
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/docker/docker@v20.10.7+incompatible
23.0.11

Open the chart page →

2,435
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

8,408
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

3,659
overlorddoubanVerified publisher0.2.21 of 1See more

overlord douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
douz/overlord:latestf2bc7fc068c1
github.com/docker/docker@v1.13.1
23.0.11

Open the chart page →

3,693
drogue-cloud-metricsdrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.26.038d40a760569
github.com/docker/docker@v20.10.5+incompatible
23.0.11

Open the chart page →

13,558
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
23.0.11

Open the chart page →

20,205
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

7,255
openfaas2eclipse-aeriosVerified publisher12.0.51 of 6See more

openfaas2 eclipse-aerios 12.0.5

1 of the 6 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
prom/prometheus:v2.51.24f6c47e39a90
github.com/docker/docker@v25.0.3+incompatible
25.0.5

Open the chart page →

6,678
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

7,327
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

7,510
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
github.com/docker/docker@v20.10.8+incompatible
23.0.11

Open the chart page →

7,617
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/docker/docker@v20.10.12+incompatible
23.0.11

Open the chart page →

13,450
mission-control-tenantflanksourceVerified publisher1.0.921 of 3See more

mission-control-tenant flanksource 1.0.92

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
github.com/docker/docker@v23.0.0-rc.1+incompatible
23.0.11

Open the chart page →

5,684
galoygaloymoney0.34.71 of 24See more

galoy galoymoney 0.34.7

1 of the 24 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
oryd/kratos:v1.0.0d06fc5845f63
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

8,677
galoygaloymoney20.34.71 of 24See more

galoy galoymoney2 0.34.7

1 of the 24 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
oryd/kratos:v1.0.0d06fc5845f63
github.com/docker/docker@v20.10.24+incompatible
23.0.11

Open the chart page →

8,677
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
github.com/docker/docker@v20.10.3-0.20220121014307-40bb9831756f+incompatible
23.0.11

Open the chart page →

4,547
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-29018.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
23.0.11

Open the chart page →

7,510

Container images carrying it

262 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/docker/docker@v20.10.24+incompatible
23.0.11
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
github.com/docker/docker@v20.10.24+incompatible
23.0.11
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
github.com/docker/docker@v20.10.12+incompatible
23.0.11
1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/docker/docker@v1.4.2-0.20191121165722-d1d5f6476656
23.0.11
1
quay.io/operator-framework/olmf9ea8cef95ac
github.com/docker/docker@v20.10.21+incompatible
23.0.11
1
quay.io/prometheus/prometheus:v2.39.14748e26f9369
github.com/docker/docker@v20.10.18+incompatible
23.0.11
1
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
github.com/docker/docker@v20.10.17+incompatible
23.0.11
1
quay.io/prometheus/prometheus:v2.33.591100b06e86d
github.com/docker/docker@v20.10.12+incompatible
23.0.11
1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
23.0.11
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/docker/docker@v23.0.5+incompatible
23.0.11
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/docker/docker@v20.10.3+incompatible
23.0.11
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
github.com/docker/docker@v17.12.1-ce+incompatible
23.0.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.