StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
507
of 17,787 indexed, latest versions
Container images
503
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 507 of 17,787 indexed charts deploy, on 503 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed503
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

507 by stars
ChartLatestAffected imagesRadar Score
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
ip@1.1.5
no fix listed

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
ip@1.1.5
no fix listed

Open the chart page →

22,665
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

503 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
ip@2.0.0
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
ip@2.0.0
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
ip@2.0.0
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
ip@2.0.0
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
ip@2.0.0
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
ip@1.1.5
no fix listed
1
willwill/kube-slack:v4.1.1d443017aae98
ip@1.1.5
no fix listed
1
winfred008/amazon:910a68de5b398
ip@2.0.0
no fix listed
1
wiremind/scrapoxy:lateste7048929a676
ip@1.1.5
no fix listed
1
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
ip@1.1.8
no fix listed
1
zazuko/trifid:2.3.7054be137de70
ip@1.1.5
no fix listed
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed
1
zooz/predator:1.6f491d1f7a865
ip@1.1.5
no fix listed
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
ip@1.1.5
no fix listed
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
ip@1.1.5
no fix listed
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
ip@1.1.5
no fix listed
1
ghcr.io/0xemma/reddark:main2a115e991894
ip@2.0.0
no fix listed
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
ip@1.1.5
no fix listed
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip@2.0.0
no fix listed
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
ip@2.0.0
no fix listed
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
ip@2.0.0
no fix listed
1
ghcr.io/ajnart/homarr:lateste103abadfb52
ip@2.0.0
no fix listed
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
ip@2.0.0
no fix listed
1
ghcr.io/beluga-cloud/actual/actualserver:23.12.1c8a0d5ec5a12
ip@2.0.0
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
ip@2.0.0
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ip@1.1.9
no fix listed
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
ip@2.0.0
no fix listed
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
ip@1.1.5
no fix listed
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
ip@1.1.5
no fix listed
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
ip@1.1.5
no fix listed
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
ip@1.1.5
no fix listed
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
ip@1.1.5
no fix listed
1
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
ip@2.0.0
no fix listed
1
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
ip@2.0.0
no fix listed
1
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
ip@1.1.8
no fix listed
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
ip@1.1.8
no fix listed
1
ghcr.io/data-fair/metrics:0a8d40779eeae
ip@1.1.5
no fix listed
1
ghcr.io/data-fair/portals:18b621866ceb2
ip@2.0.0
no fix listed
1
ghcr.io/data-fair/processings:15a9216989707
ip@2.0.0
no fix listed
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
ip@1.1.5
no fix listed
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
ip@2.0.0
no fix listed
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
ip@1.1.5
no fix listed
1
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
ip@1.1.5
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
ip@1.1.5
no fix listed
1
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
ip@2.0.0
no fix listed
1
ghcr.io/k10app/catalog:latest639c980be0f1
ip@2.0.0
no fix listed
1
ghcr.io/k10app/order:lateste1017d0dbd78
ip@2.0.0
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
ip@1.1.5
no fix listed
1
ghcr.io/kubedb/mongo-gui:latestee0354b7a57a
ip@1.1.8
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.