StackRadar

CVE-2024-31141

Medium

Advisory

Published 19 Nov 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
1 of 1
affected package

Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven2.3.0, 2.3.1, 2.4.0, 2.4.1+22 more3.7.1107
OSV records
GHSA-2x2g-32r7-p4x8

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
kafka-clients@3.5.0
3.7.1

Open the chart page →

1,597
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.7.1

Open the chart page →

4,245
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
kafka-clients@3.0.1
3.7.1

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
3.7.1

Open the chart page →

12,513
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
kafka-clients@2.4.1
3.7.1

Open the chart page →

13,767
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.7.1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.7.1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.7.1
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.7.1

Open the chart page →

13,646
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
kafka-clients@2.3.0
3.7.1

Open the chart page →

4,538
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
kafka-clients@2.8.2
3.7.1

Open the chart page →

4,240
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
3.7.1

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.7.1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.7.1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.7.1
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.7.1

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
3.7.1

Open the chart page →

12,455
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.7.1

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
3.7.1

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
3.7.1

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-31141.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
3.7.1

Open the chart page →

5,806

Container images carrying it

107 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
kafka-clients@2.8.1
3.7.1
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
kafka-clients@3.7.0
3.7.1
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
kafka-clients@2.8.2
3.7.1
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
kafka-clients@3.5.1
3.7.1
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
3.7.1
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
kafka-clients@3.3.2
3.7.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
kafka-clients@3.5.1
3.7.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.