CVE-2024-3220
LowAdvisory
Published 19 Feb 2025In the index since 6 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 2.3
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.14.0 | 3 |
| python-3.14apk | 3.14.2-r2 | 3.14.2-r3 | 4 |
- OSV records
- CGA-prhm-5jjf-mx6jBIT-python-2024-3220
- Also known as
- BIT-python-min-2024-3220, CGA-q3wh-9xpc-hjfq, PSF-2025-2
Charts affected
4 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| thehivestrangebee-helmOfficialVerified publisher | 1.0.6 | 1 of 7See more | 16,210 |
| arlas-aiasarlas-stackVerified publisher | 28.8.0 | 1 of 22See more | 40,238 |
| deployhubdeployhubVerified publisher | 10.0.415 | 4 of 11See more | 11,160 |
| automx2oleds-helm-chartsVerified publisher | 1.0.5 | 1 of 1See more | 5,288 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bitnamilegacy/ | 2b7a217999a1 | python | 3.14.0 | 1 |
| oled01/ | 05d3e398e675 | python | 3.14.0 | 1 |
| ghcr.io/ | 8ac53eb38393 | python | 3.14.0 | 1 |
| quay.io/ | 97b7f49eec76 | python-3.14 | 3.14.2-r3 | 1 |
| quay.io/ | 8a4150e94a45 | python-3.14 | 3.14.2-r3 | 1 |
| quay.io/ | f5c4c8adfc82 | python-3.14 | 3.14.2-r3 | 1 |
| quay.io/ | b5054bd4e97a | python-3.14 | 3.14.2-r3 | 1 |