StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
501
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 501 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed501
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

501 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
ip@2.0.0
no fix listed
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
ip@1.1.5
no fix listed
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
ip@1.1.5
no fix listed
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
ip@2.0.0
no fix listed
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
ip@1.1.5
no fix listed
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
ip@2.0.0
no fix listed
1
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
ip@2.0.1
no fix listed
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
ip@2.0.0
no fix listed
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
ip@2.0.0
no fix listed
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
ip@1.1.5
no fix listed
1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
ip@1.1.5
no fix listed
1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
ip@1.1.5
no fix listed
1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
ip@1.1.5
no fix listed
1
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
ip@2.0.0
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
ip@1.1.8
no fix listed
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
ip@2.0.0
no fix listed
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
ip@1.1.5
no fix listed
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
ip@2.0.0
no fix listed
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
ip@2.0.1
no fix listed
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
ip@2.0.0
no fix listed
1
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
ip@2.0.0
no fix listed
1
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
ip@2.0.0
no fix listed
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
ip@2.0.0
no fix listed
1
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
ip@2.0.0
no fix listed
1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
ip@2.0.0
no fix listed
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
ip@1.1.5
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
ip@2.0.0
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip@2.0.0
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip@1.1.8
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
ip@2.0.0
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
ip@2.0.0
no fix listed
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
ip@1.1.5
no fix listed
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ip@1.1.5
no fix listed
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
ip@1.1.5
no fix listed
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
ip@1.1.5
no fix listed
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
ip@1.1.5
no fix listed
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
ip@1.1.5
no fix listed
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ip@1.1.5
no fix listed
1
quay.io/netwarps/blockscoutbecd3e39360a
ip@1.1.5
no fix listed
1
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
ip@2.0.0
no fix listed
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
ip@1.1.5
no fix listed
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
ip@1.1.5
no fix listed
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
ip@1.1.5
no fix listed
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
ip@1.1.5
no fix listed
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
ip@2.0.0
no fix listed
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
ip@1.1.5
no fix listed
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
ip@1.1.8
no fix listed
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
ip@1.1.5
no fix listed
1
quay.io/wekan/wekan:v5.65cb17600883a3
ip@1.1.5
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
ip@1.1.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.