StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
505
of 17,787 indexed, latest versions
Container images
501
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 505 of 17,787 indexed charts deploy, on 501 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed501
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

505 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

501 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nottiey/mynodejswebapp:latest9c35a24c9eb3
ip@2.0.0
no fix listed
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
ip@1.1.5
no fix listed
1
okaforuchena/uo-docker:V1.0.0004e81250f48
ip@2.0.0
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
ip@1.1.5
no fix listed
1
ondrejsika/parking:latestb1fd497416c8
ip@1.1.5
no fix listed
1
ooghenekaro/amazon:latest03394ba1d6d8
ip@2.0.0
no fix listed
1
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
ip@2.0.0
no fix listed
1
ooghenekaro/nodejswebapp:latestea5b71588a76
ip@2.0.0
no fix listed
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
ip@2.0.0
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
ip@2.0.0
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
ip@2.0.0
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
ip@2.0.0
no fix listed
1
openemr/openemr:6.1.089eaa6d9a4e3
ip@1.1.5
no fix listed
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
ip@1.1.5
no fix listed
1
openproject/community:12.0.2734743d11094
ip@1.1.5
no fix listed
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
ip@1.1.5
no fix listed
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
ip@1.1.5
no fix listed
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
ip@2.0.0
no fix listed
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
ip@2.0.0
no fix listed
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ip@1.1.5
no fix listed
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
ip@1.1.5
no fix listed
1
patdada/bella-docker:v1.0.075127147a624
ip@1.1.5
no fix listed
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
ip@1.1.5
no fix listed
1
pawelmalak/flame:2.1.193e7b0abb603
ip@1.1.5
no fix listed
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
ip@1.1.5
no fix listed
1
penpotapp/exporter:2.2.15c835ffd87ab
ip@2.0.0
no fix listed
1
phntom/camo:2.3.1a9b1304d6c71
ip@1.1.5
no fix listed
1
phntom/codimd:2.4.31b9aafbb62e6
ip@1.1.5
no fix listed
1
plumdog/db-operator:latest0c2fa2db0357
ip@1.1.5
no fix listed
1
polonel/trudesk:1.2.60cf6513f6fe3
ip@1.1.5
no fix listed
1
project2team4/react:latest3ff031a08887
ip@1.1.5
no fix listed
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
ip@2.0.0
no fix listed
1
psorab/elibrary:latest53b68896c4ce
ip@2.0.0
no fix listed
1
pumejlab/nodejs-webapp:latestf563eabcb819
ip@2.0.0
no fix listed
1
punkerside/noroot:v0.0.7be20c81d6ca1
ip@1.1.8
no fix listed
1
rakii8585/angular-node-webapp:latest026082a515ac
ip@1.1.5
no fix listed
1
redis/redisinsight:2.46699d341bd329
ip@2.0.0
no fix listed
1
refar/apm-portal:v5.7.1dcca8e4477a6
ip@1.1.5
no fix listed
1
requarks/wiki:canary-2.5.2438b5865a7386c
ip@1.1.5
no fix listed
1
rlex/jsonvisio:1.9.5cd50ff65118e
ip@1.1.5
no fix listed
1
roadiehq/community-backstage-image:latestef355bf5b639
ip@1.1.5
no fix listed
1
robotshop/rs-cart:latest388349d5cb3c
ip@1.1.5
no fix listed
1
robotshop/rs-catalogue:latestd545747c1b97
ip@1.1.5
no fix listed
1
robotshop/rs-user:latestea509182c180
ip@1.1.5
no fix listed
1
samajh/alprbackend:latestea742b4372ad
ip@1.1.5
no fix listed
1
samajh/alprfrontend:latest05ef4fddbb75
ip@1.1.8
no fix listed
1
shahanafarooqui/rtl:0.11.0d0cd3d868aca
ip@1.1.5
no fix listed
1
shinobisystems/shinobi:dev3ca746937856
ip@1.1.5
no fix listed
1
shinobisystems/shinobi:latestc2f5ce2e1067
ip@1.1.5
no fix listed
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
ip@1.1.5
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.