StackRadar

CVE-2024-33601

High

Advisory

Published 6 May 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
765
of 17,787 indexed, latest versions
Container images
729
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 765 of 17,787 indexed charts deploy, on 729 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+29 more2.23-0ubuntu11.3+esm7, 2.27-3ubuntu1.6+esm3, 2.31-0ubuntu9.16, 2.35-0ubuntu3.8+2 more720
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibcapk2.37-r6, 2.38-r62.39-r52
OSV records
CGA-34v4-vwhj-84jhDEBIAN-CVE-2024-33601UBUNTU-CVE-2024-33601
Also known as
CGA-4vwf-3pqq-r947, USN-6804-1

Charts affected

765 by stars
ChartLatestAffected imagesRadar Score
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16

Open the chart page →

9,225
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16

Open the chart page →

9,225
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
glibc@2.36-9
2.36-9+deb12u7

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16

Open the chart page →

28,699
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
glibc@2.27-3ubuntu1.2
2.27-3ubuntu1.6+esm3

Open the chart page →

10,857
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16

Open the chart page →

15,287
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
openebs/node-disk-operator:2.1.06afe2123c457
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8

Open the chart page →

10,568
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
glibc@2.36-9+deb12u3
2.36-9+deb12u7

Open the chart page →

14,618
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
glibc@2.35-0ubuntu3.5
2.35-0ubuntu3.8

Open the chart page →

9,296
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
glibc@2.36-9+deb12u3
2.36-9+deb12u7

Open the chart page →

5,548
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
glibc@2.39-0ubuntu8.1
2.39-0ubuntu8.2

Open the chart page →

2,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
glibc@2.36-9+deb12u4
2.36-9+deb12u7

Open the chart page →

2,674
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm3

Open the chart page →

2,464
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2024-33601.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
glibc@2.27-3ubuntu1.4
2.27-3ubuntu1.6+esm3
yandex/clickhouse-server:21.3.204eccfffb01d7
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16

Open the chart page →

9,250

Container images carrying it

729 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
glibc@2.27-3ubuntu1.2
2.27-3ubuntu1.6+esm3
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
glibc@2.36-9+deb12u3
2.36-9+deb12u7
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm3
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm3
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
glibc@2.35-0ubuntu3
2.35-0ubuntu3.8
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
2
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
glibc@2.36-9+deb12u1
2.36-9+deb12u7
1
5200710/hadoop:3.2.3-java8092d3088a5fb
glibc@2.31-0ubuntu9.14
2.31-0ubuntu9.16
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
glibc@2.27-3ubuntu1
2.27-3ubuntu1.6+esm3
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
glibc@2.31-0ubuntu9.1
2.31-0ubuntu9.16
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
1
akaunting/akaunting:3.0.1552811b36ec3a
glibc@2.36-9
2.36-9+deb12u7
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
glibc@2.27-3ubuntu1.6
2.27-3ubuntu1.6+esm3
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
glibc@2.35-0ubuntu3.4
2.35-0ubuntu3.8
1
anguda/ant-media:2.5c435285fc241
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
glibc@2.36-9+deb12u3
2.36-9+deb12u7
1
apache/airflow:2.8.4-python3.964e58748b6b9
glibc@2.36-9+deb12u4
2.36-9+deb12u7
1
apache/airflow:2.8.1e5560ad0b86e
glibc@2.36-9+deb12u4
2.36-9+deb12u7
1
apache/druid:29.0.10cef139b6bf1
glibc@2.36-9+deb12u4
2.36-9+deb12u7
1
apache/iotdb:0.13.3-nodeafa47bf1692a
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
1
apachepulsar/pulsar:2.9.0d056c89b7131
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
1
apachepulsar/pulsar:2.8.2d538416d5afe
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
1
apache/rocketmq-exporter:0.0.2c8fb51195444
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.8
1
apache/skywalking-oap-server:9.2.0133d35d2c263
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
1
apache/skywalking-ui:9.2.0295f1dc87d98
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
1
apache/skywalking-ui:8.9.180530f0308a5
glibc@2.31-0ubuntu9.2
2.31-0ubuntu9.16
1
apache/superset:4.0.1ab9467fd712c
glibc@2.36-9+deb12u6
2.36-9+deb12u7
1
apache/tika:2.9.0.092d055a84e9e
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
glibc@2.23-0ubuntu10
2.23-0ubuntu11.3+esm7
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
glibc@2.31-0ubuntu9.12
2.31-0ubuntu9.16
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
1
assistiot/identity-manager_db:latest0d3e6d35f168
glibc@2.36-9+deb12u3
2.36-9+deb12u7
1
assistiot/location_processing:lateste9bae124095f
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
1
assistiot/open_api_backend:1.1.230812ba93555
glibc@2.35-0ubuntu3.5
2.35-0ubuntu3.8
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
glibc@2.36-9+deb12u4
2.36-9+deb12u7
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
glibc@2.36-9+deb12u4
2.36-9+deb12u7
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
glibc@2.36-9+deb12u1
2.36-9+deb12u7
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
1
atlassian/confluence-server:7.10.03b9222ab32ef
glibc@2.35-0ubuntu3.1
2.35-0ubuntu3.8
1
atlassian/jira-software:8.14.037bc46cbec1a
glibc@2.35-0ubuntu3.6
2.35-0ubuntu3.8
1
avinash263/pyredis263:latestaa2b8727f1a6
glibc@2.36-9
2.36-9+deb12u7
1
avzini/web-app:latestf40b30210ed0
glibc@2.36-9+deb12u3
2.36-9+deb12u7
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
glibc@2.31-0ubuntu9.7
2.31-0ubuntu9.16
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
glibc@2.31-0ubuntu9.9
2.31-0ubuntu9.16
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.