StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
501
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 501 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed501
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

501 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
felipecs8/app-movies-series:v14e51693fcdf5
ip@1.1.5
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip@2.0.0
no fix listed
1
fiware/idm:8.3.3a1b6ed4ae84f
ip@1.1.5
no fix listed
1
fiware/iotagent-json:3.1.0879b21a0d36d
ip@2.0.0
no fix listed
1
fiware/iotagent-ul:1.14.0fe11f55a926d
ip@1.1.5
no fix listed
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ip@1.1.5
no fix listed
1
frappe/frappe-socketio:v13.4.12095767a9e82
ip@1.1.5
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
ip@1.1.5
no fix listed
1
gethue/hue:4.11.011b649636e68
ip@1.1.5
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
ip@1.1.5
no fix listed
1
glenndehaan/contentbridge:latest99b9e4f73848
ip@2.0.0
no fix listed
1
gonzague/monopoly:latest70465995deea
ip@1.1.5
no fix listed
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
ip@1.1.5
no fix listed
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
ip@1.1.5
no fix listed
1
gristlabs/grist:0.7.96e71b1914a7e
ip@1.1.5
no fix listed
1
gtato/demo-multiclus-registrator:1.0.09a744588fab3
ip@1.1.5
no fix listed
1
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
ip@1.1.5
no fix listed
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ip@1.1.5
no fix listed
1
halkeye/hubot:latest9764d2202130
ip@1.1.5
no fix listed
1
halkeye/irslackd:latest7638bfba70b0
ip@1.1.5
no fix listed
1
hamid2021/nodejs-dockercli:latest429d99890c3c
ip@2.0.0
no fix listed
1
hansehe/graphql-gateway:1.0.458e09540afbc
ip@2.0.0
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
ip@1.1.5
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ip@2.0.0
no fix listed
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ip@2.0.0
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
ip@2.0.0
no fix listed
1
henrywhitaker3/speedtest-tracker:latest47159a940229
ip@1.1.5
no fix listed
1
heywood8/redisinsight:2.28.00bc9ab313d37
ip@2.0.0
no fix listed
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
ip@1.1.5
no fix listed
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ip@1.1.5
no fix listed
1
hugohg34/server:0.0.2503e5d8960ff
ip@1.1.5
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
ip@1.1.5
no fix listed
1
i4trust/pdc-portal:2.0.03e77858e1219
ip@1.1.5
no fix listed
1
ianw/quickchart:v1.7.1dc49dd460c37
ip@1.1.5
no fix listed
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
ip@1.1.6
no fix listed
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
ip@1.1.5
no fix listed
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
ip@1.1.5
no fix listed
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ip@1.1.5
no fix listed
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
ip@1.1.5
no fix listed
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
ip@1.1.5
no fix listed
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
ip@1.1.5
no fix listed
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ip@1.1.5
no fix listed
1
ibmcom/microclimate-portal:latested5505e5c7ec
ip@1.0.1
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
ip@1.1.5
no fix listed
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ip@1.1.5
no fix listed
1
improwised/erpnext-worker:v13.4.197280b55cbd4
ip@1.1.5
no fix listed
1
inseefrlab/shelly:cloudshell31f04ca7436b
ip@1.1.5
no fix listed
1
instructure/kinesalite:latest34400d82f28f
ip@2.0.0
no fix listed
1
intelloop/atlas-cmms-frontend:v1.5.12409c2a00ab6
ip@2.0.0
no fix listed
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
ip@1.1.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.