StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
501
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 501 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed501
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

501 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/kibana:7.17.3e2e2031c15be
ip@1.1.5
no fix listed
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip@2.0.0
no fix listed
1
library/node:16.13.0-alpine60ef0bed1dc2
ip@1.1.5
no fix listed
1
library/node:16.20f77a1aef2da8
ip@2.0.0
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
ip@1.1.5
no fix listed
1
linuxserver/code-server:4.10.1a5e43a05ae79
ip@1.1.5
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
ip@1.1.5
no fix listed
1
linuxserver/overseerr:1.35.06108ed066d4a
ip@2.0.0
no fix listed
1
lissy93/dashy:2.0.51991f7be5ed0
ip@1.1.5
no fix listed
1
localstack/localstack:3.19d278167f2b7
ip@2.0.0
no fix listed
1
loftsh/jspolicy:0.2.225deb9bd2683
ip@2.0.0
no fix listed
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
ip@2.0.0
no fix listed
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
ip@1.1.5
no fix listed
1
louislam/uptime-kuma:1.18.5a84767d7934f
ip@1.1.8
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
ip@1.1.5
node-ip@1.1.5-5
no fix listed
no fix listed
1
lsstsqre/squareone:0.4.09ded78e7fe03
ip@1.1.5
no fix listed
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
ip@1.1.5
no fix listed
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
ip@2.0.0
no fix listed
1
luligu/matterbridge:3.0.28f97884bebc2
ip@1.1.9
no fix listed
1
maissacrement/pock8snodejs:0.0.16da0db1159da
ip@2.0.0
no fix listed
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
ip@2.0.0
no fix listed
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ip@2.0.0
no fix listed
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
ip@1.1.5
no fix listed
1
milesmcc/shynet:v0.13.1ba54f7797a6b
ip@1.1.5
no fix listed
1
milesmcc/shynet:v0.12.0e821e31140f7
ip@1.1.5
no fix listed
1
minddocdev/hubot:0.1.96c60b11a4fa7
ip@1.1.5
no fix listed
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
ip@1.1.5
no fix listed
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
ip@2.0.0
no fix listed
1
misskey/misskey:12.110.1e08b7c478093
ip@1.1.5
no fix listed
1
mitchxxx/amazon:214e72480ec63a
ip@2.0.0
no fix listed
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip@2.0.0
no fix listed
1
moreillon/api-proxy:2373c1953739ef6956b5
ip@2.0.0
no fix listed
1
moreillon/camera-proxy:latestce60056b50c2
ip@2.0.0
no fix listed
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
ip@1.1.5
no fix listed
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
ip@1.1.8
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
ip@2.0.0
no fix listed
1
mozilla/sentencecollector:2.0.91da6ff5c4895
ip@1.1.5
no fix listed
1
mpopoola1/nodejsapp:latest061fc532de7d
ip@2.0.0
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ip@1.1.5
no fix listed
1
n8nio/n8n:0.212.0a9195bc499a3
ip@2.0.0
no fix listed
1
n8nio/n8n:1.33.1dd171d45102a
ip@2.0.0
no fix listed
1
neoskop/papergirl:3.2.67f52b5949f03
ip@2.0.0
no fix listed
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
ip@1.1.5
no fix listed
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ip@1.1.5
no fix listed
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
ip@1.1.8
no fix listed
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
ip@1.1.8
no fix listed
1
nodered/node-red:2.2.2e131dcadfe92
ip@1.1.5
no fix listed
1
nodered/node-red:3.0.2-18e2632a7a35dd
ip@2.0.0
no fix listed
1
nodered/node-red-docker:0.19.6-v8070643219ea2
ip@1.1.5
no fix listed
1
nonkronk/tristian-id:latest0a3694d70647
ip@1.1.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.