StackRadar

CVE-2024-32007

Medium

Advisory

Published 19 Jul 2024In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Apache CXF Denial of Service vulnerability in JOSE

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
cxf-rt-rs-security-josemaven3.2.2, 3.4.0, 3.4.4, 3.4.5+2 more3.5.9, 4.0.58
OSV records
GHSA-6pff-fmh2-4mmf

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.10.0c8f3ebd2a934
cxf-rt-rs-security-jose@4.0.2
4.0.5

Open the chart page →

10,530
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
cxf-rt-rs-security-jose@3.4.0
3.5.9

Open the chart page →

10,730
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
cxf-rt-rs-security-jose@3.5.5
3.5.9

Open the chart page →

13,479
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
cxf-rt-rs-security-jose@3.4.5
3.5.9

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
cxf-rt-rs-security-jose@3.4.5
3.5.9

Open the chart page →

16,975
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-rt-rs-security-jose@3.4.0
3.5.9

Open the chart page →

5,806
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cxf-rt-rs-security-jose@3.2.2
3.5.9

Open the chart page →

39,349
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
cxf-rt-rs-security-jose@3.2.2
3.5.9

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-rt-rs-security-jose@3.4.4
3.5.9

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-rt-rs-security-jose@3.4.4
3.5.9

Open the chart page →

10,603
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-32007.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-rt-rs-security-jose@3.4.0
3.5.9

Open the chart page →

5,806

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-rt-rs-security-jose@3.4.0
3.5.9
2
opensearchproject/opensearch:2.1.04254021a8c71
cxf-rt-rs-security-jose@3.4.5
3.5.9
2
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-rt-rs-security-jose@3.4.4
3.5.9
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
cxf-rt-rs-security-jose@3.2.2
3.5.9
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
cxf-rt-rs-security-jose@3.4.0
3.5.9
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cxf-rt-rs-security-jose@3.2.2
3.5.9
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
cxf-rt-rs-security-jose@3.5.5
3.5.9
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
cxf-rt-rs-security-jose@4.0.2
4.0.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.