StackRadar

CVE-2024-29415

High

Advisory

Published 27 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.083
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
506
of 17,781 indexed, latest versions
Container images
502
deployed by those charts
Fix available
None
affected packages

ip SSRF improper categorization in isPublic

Carried by container images the latest versions of 506 of 17,781 indexed charts deploy, on 502 images.

Affected packageAffected versionsFixed inImages
ipnpm1.0.1, 1.1.5, 1.1.6, 1.1.8+3 moreno fix listed502
node-ipdeb1.1.5-5, 2.0.0+~1.1.0-1ubuntu1no fix listed3
OSV records
GHSA-2p57-rm9w-gvfpUBUNTU-CVE-2024-29415

Charts affected

506 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
ip@1.1.5
no fix listed

Open the chart page →

22,665
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
ip@2.0.0
no fix listed
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ip@2.0.0
no fix listed
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ip@2.0.0
no fix listed
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
ip@2.0.0
no fix listed

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
ip@1.1.5
no fix listed

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ip@1.1.5
no fix listed

Open the chart page →

1,309
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ip@2.0.0
no fix listed

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-29415.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
ip@1.1.5
no fix listed

Open the chart page →

3,118

Container images carrying it

502 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ip@1.1.5
no fix listed
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
ip@1.1.5
no fix listed
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
ip@1.1.5
no fix listed
4
kodekloud/examplevotingapp_result:v1e510023fdf38
ip@2.0.0
no fix listed
4
oscarsotosanchez/server:v1.06e2e1279126b
ip@1.1.5
no fix listed
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
ip@1.1.5
no fix listed
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip@2.0.0
no fix listed
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ip@2.0.0
no fix listed
4
assistiot/dlt_api:2.0.0e36a8922fa0c
ip@2.0.0
no fix listed
3
dgraph/dgraph:v21.12.03b55ea83fffe
ip@1.1.5
no fix listed
3
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
ip@1.1.5
no fix listed
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ip@1.1.5
no fix listed
3
pantsel/konga:latestc8172b75607d
ip@1.1.5
no fix listed
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/emails:59b64c36c866b3555c135c70de76a884e63f86197d2d6d7c099a
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/schema:59b64c36c866b3555c135c70de76a884e63f8619931d1f6e5ad4
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/server:59b64c36c866b3555c135c70de76a884e63f86196d3899d281cc
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/storage:59b64c36c866b3555c135c70de76a884e63f86199808dac13353
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/tokens:59b64c36c866b3555c135c70de76a884e63f86190f3416d940b4
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/usage:59b64c36c866b3555c135c70de76a884e63f861953619ee7614e
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/usage-ingestor:59b64c36c866b3555c135c70de76a884e63f861947b87c071af4
ip@2.0.0
no fix listed
3
ghcr.io/kamilkisiela/graphql-hive/webhooks:59b64c36c866b3555c135c70de76a884e63f861918a5c5b5b671
ip@2.0.0
no fix listed
3
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
ip@2.0.0
no fix listed
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
ip@1.1.5
no fix listed
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
ip@1.1.5
no fix listed
2
ethersphere/bee-localchain:latest0558799ca992
ip@2.0.0
no fix listed
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
ip@1.1.5
no fix listed
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ip@1.1.5
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
ip@2.0.0
no fix listed
2
governify/assets-manager:v1.4.12987672448c7
ip@1.1.5
no fix listed
2
governify/director:v1.4.0608c6940bb98
ip@1.1.5
no fix listed
2
governify/registry:v3.4.0d3f37f4f8168
ip@1.1.5
no fix listed
2
governify/render:v2.2.0daeca1ce28e6
ip@1.1.5
no fix listed
2
governify/reporter:v2.2.038595913458f
ip@1.1.5
no fix listed
2
gradiant/open5gs-webui:2.7.5fbd10c017541
ip@2.0.0
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
ip@1.1.5
no fix listed
2
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
ip@1.1.5
no fix listed
2
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
ip@1.1.5
no fix listed
2
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
ip@1.1.5
no fix listed
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
ip@1.1.5
no fix listed
2
krtk6160/galoy-nostrcc82a694f818
ip@2.0.0
no fix listed
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
ip@2.0.0
no fix listed
2
langgenius/dify-sandbox:0.2.009b7e8705673
ip@2.0.0
no fix listed
2
library/mongo-express:1.0.2:latest1b23d7976f02
ip@2.0.0
no fix listed
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
ip@1.1.5
no fix listed
2
mesosphere/kommander:6.100.13917e82333a9
ip@1.1.5
no fix listed
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ip@1.1.5
no fix listed
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ip@1.1.5
no fix listed
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
ip@1.1.5
no fix listed
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.