StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
501
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 501 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed501
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

501 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bnwokoye/nodejswebapp:latest74de7dc7ebfb
ip@2.0.0
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ip@1.1.5
no fix listed
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
ip@1.1.5
no fix listed
1
catalysm/csmm:latestf003b35f54d9
ip@2.0.0
no fix listed
1
ccjacobs14/amazon:59a9b14a6f09e
ip@2.0.0
no fix listed
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
ip@2.0.1
no fix listed
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip@2.0.0
no fix listed
1
chatwoot/chatwoot:v4.15.167ebc751c171
ip@1.1.5
no fix listed
1
chocobozzz/peertube:v8.1.5052712130691
ip@2.0.1
no fix listed
1
cnieg/maildev:v1.1.998ee05668915
ip@1.1.5
no fix listed
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ip@2.0.0
no fix listed
1
codercom/code-server:4.11.0-debian1e2cc688008e
ip@1.1.5
no fix listed
1
codercom/code-server:3.10.247605610ad8d
ip@1.1.5
no fix listed
1
coldatom/containers-security-api:latesteae9e82da080
ip@2.0.0
no fix listed
1
coldatom/containers-security-front:latest7c2fbbb41bcf
ip@2.0.0
no fix listed
1
conduction/conduction-ui-app:devd591f5e6f2a9
ip@1.1.5
no fix listed
1
countly/api:25.05.4f4cc7447c4f5
ip@2.0.1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
ip@2.0.1
no fix listed
1
countly/frontend:25.05.42acbc11499b6
ip@2.0.1
no fix listed
1
cryptexlabs/authf:0.12.11189c07411d7c
ip@2.0.0
no fix listed
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
ip@2.0.0
no fix listed
1
dacinfomotion/h2p:latest68fa393b472c
ip@2.0.0
no fix listed
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
ip@2.0.0
no fix listed
1
daskdev/dask-notebook:1.1.0052630f5ca04
ip@1.1.5
no fix listed
1
datarhei/restreamer:0.6.4655e12f9eeed
ip@1.1.5
no fix listed
1
davdiv/musicociel:deva85f99be882c
ip@2.0.0
no fix listed
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
ip@1.1.5
no fix listed
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
ip@1.1.5
no fix listed
1
decayofmind/hubot:3.3.21e18e92fe694
ip@1.1.5
no fix listed
1
denisshav/backend:latest4cc8dc5a4499
ip@1.1.5
no fix listed
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip@1.1.5
no fix listed
1
devspacecloud/ui:0.3.3deef55ff29a7
ip@1.1.5
no fix listed
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
ip@1.1.8
no fix listed
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
ip@2.0.0
no fix listed
1
ealen/echo-server:0.6.0359761caae37
ip@1.1.8
no fix listed
1
eameti/node-app:latestf36642affa86
ip@1.1.5
no fix listed
1
electerious/ackee:3.2.05e7173fa321c
ip@1.1.5
no fix listed
1
enketo/enketo-express:3.0.4dcad9c2273f6
ip@1.1.5
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ip@1.1.5
no fix listed
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
ip@1.1.5
no fix listed
1
ethersphere/bzz-token-service:latest7624f11a72ad
ip@1.1.5
no fix listed
1
ethersphere/etherproxy:1.0.056029b0985f4
ip@2.0.0
no fix listed
1
ethersphere/onboarding-faucet:0.3.0513154aab230
ip@1.1.5
no fix listed
1
ethpandaops/blobscan:latest7a9ab6370657
ip@1.1.5
no fix listed
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
ip@2.0.0
no fix listed
1
factly/mande-web:0.34.1742355964b0e
ip@2.0.0
no fix listed
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
ip@2.0.0
no fix listed
1
fanzynoodle/smeejas:0.0.15f9916c1a287
ip@1.1.5
no fix listed
1
felddy/foundryvtt:0.8.36c5d90b90349
ip@1.1.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.