StackRadar

CVE-2024-33883

Medium

Advisory

Published 28 Apr 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
95
of 17,781 indexed, latest versions
Container images
87
deployed by those charts
Fix available
1 of 1
affected package

ejs lacks certain pollution protection

Carried by container images the latest versions of 95 of 17,781 indexed charts deploy, on 87 images.

Affected packageAffected versionsFixed inImages
ejsnpm0.8.8, 1.0.0, 2.3.4, 2.5.6+10 more3.1.1087
OSV records
GHSA-ghr5-ch3p-vcr6

Charts affected

95 by stars
ChartLatestAffected imagesRadar Score
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.10

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ejs@2.7.4
3.1.10

Open the chart page →

12,108
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ejs@2.7.4
3.1.10
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ejs@2.7.4
3.1.10
mojaloop/role-assignment-service:v2.1.0def4bf273721
ejs@2.7.4
3.1.10

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ejs@2.7.4
3.1.10

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.10
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ejs@2.7.4
3.1.10
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ejs@2.7.4
3.1.10

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ejs@2.7.4
3.1.10

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ejs@2.7.4
3.1.10

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
ejs@2.7.4
3.1.10

Open the chart page →

2,316
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ejs@2.7.4
3.1.10

Open the chart page →

6,438
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
ejs@3.1.8
3.1.10

Open the chart page →

6,608
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
ejs@3.1.9
3.1.10

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
ejs@3.1.9
3.1.10

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
ejs@3.1.9
3.1.10

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
ejs@3.1.9
3.1.10

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ejs@3.1.9
3.1.10

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
ejs@2.7.4
3.1.10

Open the chart page →

3,269
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
ejs@3.1.9
3.1.10

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
ejs@3.1.9
3.1.10

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
ejs@3.1.8
3.1.10

Open the chart page →

15,187
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
ejs@1.0.0
3.1.10
linuxserver/codimd:latestb801bbcf6386
ejs@2.7.4
3.1.10

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ejs@3.1.6
3.1.10

Open the chart page →

9,968
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
ejs@3.1.9
3.1.10

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
ejs@3.1.9
3.1.10

Open the chart page →

6,583
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
ejs@2.6.2
3.1.10

Open the chart page →

6,524
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
ejs@3.1.8
3.1.10

Open the chart page →

6,026
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ejs@2.7.4
3.1.10

Open the chart page →

5,215
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
ejs@3.1.8
3.1.10

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
ejs@3.1.8
3.1.10

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
ejs@2.5.6
3.1.10

Open the chart page →

3,638
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ejs@2.7.4
3.1.10

Open the chart page →

3,143
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
ejs@3.1.9
3.1.10

Open the chart page →

7,574
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
ejs@3.1.8
3.1.10

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
ejs@3.1.8
3.1.10

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
ejs@3.1.8
3.1.10

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
ejs@3.1.8
3.1.10

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
ejs@3.1.8
3.1.10

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
ejs@3.1.8
3.1.10

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
ejs@3.1.8
3.1.10

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
ejs@3.1.8
3.1.10

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ejs@3.1.7
3.1.10

Open the chart page →

11,100
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
ejs@2.7.4
3.1.10
samajh/alprfrontend:latest05ef4fddbb75
ejs@2.7.4
3.1.10

Open the chart page →

20,270
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
ejs@3.1.6
3.1.10

Open the chart page →

3,576
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
ejs@3.1.8
3.1.10

Open the chart page →

3,118
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
ejs@3.1.6
3.1.10

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-33883.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
ejs@3.1.6
3.1.10

Open the chart page →

28,605

Container images carrying it

87 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.10
3
pantsel/konga:latestc8172b75607d
ejs@0.8.8
3.1.10
3
hookiesolutions/webhookie:latest0629694246ba
ejs@3.1.6
3.1.10
2
library/arangodb:3.11.81e75d74954a4
ejs@3.1.9
3.1.10
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ejs@2.7.4
3.1.10
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ejs@2.7.4
3.1.10
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ejs@2.7.4
3.1.10
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ejs@2.7.4
3.1.10
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
ejs@2.7.4
3.1.10
2
outlinewiki/outline:0.69.1d060dcd8f9aa
ejs@3.1.8
3.1.10
2
statsd/statsd:v0.8.6dab129e74c25
ejs@2.7.4
3.1.10
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ejs@2.7.4
3.1.10
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
ejs@3.1.8
3.1.10
2
activepieces/activepieces:0.23.0c26188b44e62
ejs@3.1.9
3.1.10
1
arfath29/3-tier-app-frontend:latest384b3e377f47
ejs@2.7.4
3.1.10
1
assistiot/open_api_frontend:1.0.1f11d82defc70
ejs@3.1.8
3.1.10
1
automatischio/automatisch:0.15.03bace7a12d5f
ejs@3.1.7
3.1.10
1
catalysm/csmm:latestf003b35f54d9
ejs@3.1.6
3.1.10
1
ccjacobs14/amazon:59a9b14a6f09e
ejs@3.1.9
3.1.10
1
coldatom/containers-security-front:latest7c2fbbb41bcf
ejs@3.1.8
3.1.10
1
conduction/conduction-ui-app:devd591f5e6f2a9
ejs@2.7.4
3.1.10
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
ejs@3.1.8
3.1.10
1
felipecs8/conversor-temperatura:v1f945423be36d
ejs@3.1.8
3.1.10
1
fiware/idm:8.3.3a1b6ed4ae84f
ejs@2.7.4
3.1.10
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ejs@2.7.1
3.1.10
1
glenndehaan/api-mapper:latest6ff6310683bf
ejs@3.1.9
3.1.10
1
glenndehaan/contentbridge:latest99b9e4f73848
ejs@3.1.9
3.1.10
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
ejs@2.6.2
3.1.10
1
gristlabs/grist:0.7.96e71b1914a7e
ejs@2.7.4
3.1.10
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ejs@3.0.1
3.1.10
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ejs@3.1.9
3.1.10
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ejs@3.1.9
3.1.10
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ejs@2.6.2
3.1.10
1
ibmcom/microclimate-portal:latested5505e5c7ec
ejs@2.5.8
3.1.10
1
jayfong/yapi:1.10.2163e5d621910
ejs@2.3.4
3.1.10
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ejs@3.1.8
3.1.10
1
kubebb/component-store:latestfd8ecbd73213
ejs@3.1.9
3.1.10
1
kubebb/tamp-portal:v5.6.0fadac6d52470
ejs@2.7.4
3.1.10
1
kubebb/tdsf-portal:v5.7.0258458311bc9
ejs@2.7.4
3.1.10
1
lavandadelpatio/frontend:latest501c3f31e0bc
ejs@2.7.4
3.1.10
1
library/ghost:4.37.0767230c0f263
ejs@3.1.6
3.1.10
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
ejs@2.7.4
3.1.10
1
linuxserver/cloud9:latest45c5fe102ff3
ejs@1.0.0
3.1.10
1
linuxserver/codimd:latestb801bbcf6386
ejs@2.7.4
3.1.10
1
lissy93/dashy:2.0.51991f7be5ed0
ejs@2.7.4
3.1.10
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
ejs@3.1.7
3.1.10
1
misskey/misskey:12.110.1e08b7c478093
ejs@3.1.6
3.1.10
1
mitchxxx/amazon:214e72480ec63a
ejs@3.1.9
3.1.10
1
n8nio/n8n:0.212.0a9195bc499a3
ejs@3.1.8
3.1.10
1
n8nio/n8n:1.33.1dd171d45102a
ejs@3.1.9
3.1.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.