StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
501
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 501 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed501
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

501 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/role-assignment-service:v2.1.0def4bf273721
ip@2.0.0
no fix listed
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
ip@1.1.5
no fix listed
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
ip@2.0.0
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
ip@2.0.0
no fix listed
2
outlinewiki/outline:0.69.1d060dcd8f9aa
ip@2.0.0
no fix listed
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip@2.0.0
no fix listed
2
shahanafarooqui/rtl:0.13.3e2195188a451
ip@2.0.0
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
ip@2.0.0
no fix listed
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
ip@1.1.5
no fix listed
2
statsd/statsd:v0.8.6dab129e74c25
ip@1.1.5
no fix listed
2
taigaio/taiga-events:latest92fc0822564f
ip@2.0.0
no fix listed
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ip@1.1.5
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
ip@2.0.0
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
ip@2.0.0
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
ip@1.1.5
no fix listed
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ip@1.1.5
no fix listed
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
ip@2.0.0
no fix listed
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
ip@2.0.0
no fix listed
2
0hlov3/semaphore:v1.0.050f874ec096b
ip@2.0.0
no fix listed
1
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed
1
activepieces/activepieces:0.23.0c26188b44e62
ip@2.0.0
no fix listed
1
actualbudget/actual-server:25.3.158fecd9088b7
ip@2.0.0
no fix listed
1
adrianberger/fluxcd-webui:latest76848c0d2780
ip@1.1.5
no fix listed
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
ip@1.1.5
no fix listed
1
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
ip@1.1.5
no fix listed
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
ip@1.1.5
no fix listed
1
apimap/developer:v1.3.1406d3858e20c
ip@2.0.0
no fix listed
1
apimap/portal:v2.4.0041a4790c65c
ip@1.1.5
no fix listed
1
arfath29/3-tier-app-backend:latestee0750b18406
ip@1.1.5
no fix listed
1
arfath29/3-tier-app-frontend:latest384b3e377f47
ip@1.1.5
no fix listed
1
arturisimo/server-urjc:v1.0d8dc4430531e
ip@1.1.5
no fix listed
1
assistiot/composite-services-manager_agent-http-mqtt:latest16d21bc5e42e
ip@2.0.0
no fix listed
1
assistiot/composite-services-manager_agent-mqtt-http:latest27d58b8911cd
ip@2.0.0
no fix listed
1
assistiot/dlt_api:2.1.0c8a170683be7
ip@2.0.0
no fix listed
1
assistiot/fl_orchestrator:api-latest7473d77448e1
ip@1.1.5
no fix listed
1
assistiot/monitoring_notifying:2.0.068324d0fa5bb
ip@1.1.5
no fix listed
1
assistiot/multi-link_client:latestcf048365d042
ip@2.0.0
no fix listed
1
assistiot/multi-link_server:latestf38c76a4c960
ip@2.0.0
no fix listed
1
assistiot/open_api_frontend:1.0.1f11d82defc70
ip@1.1.5
no fix listed
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
ip@1.1.8
no fix listed
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
ip@1.1.8
no fix listed
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
ip@1.1.5
no fix listed
1
aureliengasser/http-folder:1.1.111c4318c2571
ip@1.1.5
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
ip@2.0.0
no fix listed
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ip@1.1.5
no fix listed
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
ip@2.0.0
no fix listed
1
bicarus/http-https-echo:2785dd6a7e805e
ip@2.0.0
no fix listed
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
ip@1.1.5
no fix listed
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
ip@1.1.5
no fix listed
1
blockscout/blockscout:5.1.5c365a8f2dc12
ip@1.1.8
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.