StackRadar

CVE-2024-34156

High

Advisory

Published 6 Sept 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,322
of 17,797 indexed, latest versions
Container images
2,781
deployed by those charts
Fix available
9 of 10
affected packages

Red Hat Security Advisory: skopeo security update

Carried by container images the latest versions of 2,322 of 17,797 indexed charts deploy, on 2,781 images.

Affected packageAffected versionsFixed inImages
skopeorpm2:1.11.2-0.1.el9, 2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.11.2-0.3.module+el8.8.0+22332+2132e5c3, 2:1.16.1-2.el9_52
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-66.module+el8.8.0+22332+2132e5c31
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.15-4.module+el8.8.0+22332+2132e5c31
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.11-1.module+el8.8.0+22332+2132e5c31
git-lfsrpm2.13.3-3.el8_60:3.4.1-3.el8_101
golang-1.19deb1.19.8-2no fix listed1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-1.module+el8.8.0+22332+2132e5c31
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.8.0+22332+2132e5c31
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.0-3.module+el8.8.0+22332+2132e5c31
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+134 more1.22.72,781
OSV records
DEBIAN-CVE-2024-34156RHSA-2024:11217RHSA-2024:7135RHSA-2024:7769GO-2024-3106
Also known as
BIT-golang-2024-34156, RHSA-2024:7455, RHSA-2024:7821, RHSA-2024:8111

Charts affected

2,322 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerkubesphereVerified publisher0.8.01 of 2See more

apisix-ingress-controller kubesphere 0.8.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:1.3.0412f92cde0b3
stdlib@go1.13.8
1.22.7

Open the chart page →

2,409
fluentbit-operatorkubesphereVerified publisher0.1.01 of 2See more

fluentbit-operator kubesphere 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
stdlib@go1.13.15
1.22.7

Open the chart page →

2,902
gitlabkubesphereVerified publisher4.2.36 of 17See more

gitlab kubesphere 4.2.3

6 of the 17 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
stdlib@go1.13.8
1.22.7
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
stdlib@go1.13.9
1.22.7
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
stdlib@go1.13.9
1.22.7
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
stdlib@go1.13.9
1.22.7
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
stdlib@go1.13.9
1.22.7
mirrorgitlabcontainers/kubectl:1.13.1299931bd06b41
stdlib@go1.13.3
1.22.7

Open the chart page →

38,190
harborkubesphereVerified publisher1.9.37 of 11See more

harbor kubesphere 1.9.3

7 of the 11 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
stdlib@go1.17.7
1.22.7
goharbor/harbor-core:v2.5.386bf3031f4a7
stdlib@go1.17.7
1.22.7
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
stdlib@go1.17.7
1.22.7
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
stdlib@go1.17.7
1.22.7
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
stdlib@go1.14.15
1.22.7
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
stdlib@go1.14.15
1.22.7
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
stdlib@go1.18.3
1.22.7

Open the chart page →

17,853
pvc-autoresizerkubesphereVerified publisher0.1.01 of 1See more

pvc-autoresizer kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
stdlib@go1.16.10
1.22.7

Open the chart page →

1,563
storageclass-accessorkubesphereVerified publisher0.1.01 of 1See more

storageclass-accessor kubesphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
stdlib@go1.16.10
1.22.7

Open the chart page →

1,510
ccm-qingcloudkubesphere-stable0.1.01 of 1See more

ccm-qingcloud kubesphere-stable 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.22.7

Open the chart page →

1,540
chaos-meshkubesphere-stable2.5.13 of 3See more

chaos-mesh kubesphere-stable 2.5.1

3 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
stdlib@go1.18
1.22.7
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
stdlib@go1.18
1.22.7
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
stdlib@go1.18
1.22.7

Open the chart page →

8,582
cni-hostnickubesphere-stable0.1.01 of 1See more

cni-hostnic kubesphere-stable 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
stdlib@go1.16.3
1.22.7

Open the chart page →

2,444
cranekubesphere-stable0.5.23 of 3See more

crane kubesphere-stable 0.5.2

3 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
gocrane/crane-scheduler:0.0.239ba6d11b2079
stdlib@go1.17.2
1.22.7
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
stdlib@go1.17.2
1.22.7
gocrane/craned:v0.5.1a1400909118c
stdlib@go1.17.2
1.22.7

Open the chart page →

8,903
csi-qingcloudkubesphere-stable1.4.06 of 6See more

csi-qingcloud kubesphere-stable 1.4.0

6 of the 6 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
stdlib@go1.16
1.22.7
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
stdlib@go1.16
1.22.7
csiplugin/csi-qingcloud:v1.4.00766163dc046
stdlib@go1.19.13
1.22.7
csiplugin/csi-resizer:v1.2.036c31f7e1f43
stdlib@go1.16
1.22.7
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
stdlib@go1.15
1.22.7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.22.7

Open the chart page →

12,446
curvefs-csikubesphere-stable0.1.01 of 3See more

curvefs-csi kubesphere-stable 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.22.7

Open the chart page →

2,831
deepflowkubesphere-stable6.2.6065 of 8See more

deepflow kubesphere-stable 6.2.606

5 of the 8 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.22.7
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
stdlib@go1.18.10
1.22.7
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
stdlib@go1.19.1
1.22.7
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.22.7
grafana/grafana:9.5.239c849cebccc
stdlib@go1.20.4
1.22.7

Open the chart page →

18,435
edgemeshkubesphere-stable0.1.02 of 2See more

edgemesh kubesphere-stable 0.1.0

2 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
stdlib@go1.19.13
1.22.7
kubeedge/edgemesh-server:latesta437cf5ec0ae
stdlib@go1.17.11
1.22.7

Open the chart page →

4,108
fpga-operatorkubesphere-stable2.7.43 of 7See more

fpga-operator kubesphere-stable 2.7.4

3 of the 7 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
stdlib@go1.21.6
1.22.7
inaccel/mkrt:latest187fd448b6f2
stdlib@go1.21.5
1.22.7
inaccel/reef:latestc967218739f3
stdlib@go1.21.6
1.22.7

Open the chart page →

5,771
iomeshkubesphere-stable1.1.023 of 25See more

iomesh kubesphere-stable 1.1.0

23 of the 25 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
stdlib@go1.20.3
1.22.7
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
stdlib@go1.20.3
1.22.7
iomesh/csi-driver:v2.7.25d3f9bf9240b
stdlib@go1.16.7
1.22.7
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
stdlib@go1.17.3
1.22.7
iomesh/csi-provisioner:v3.0.0f9508460b273
stdlib@go1.16.2
1.22.7
iomesh/csi-snapshotter:v6.2.2becc53e25b96
stdlib@go1.19
1.22.7
iomesh/deck:v0.1.0a31e26b6ae22
stdlib@go1.21.10
1.22.7
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
stdlib@go1.21.10
1.22.7
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
stdlib@go1.13.1
1.22.7
iomesh/livenessprobe:v2.8.0560f01510f99
stdlib@go1.18
1.22.7
iomesh/localpv-manager:v0.2.0f13deacac3f4
stdlib@go1.20.3
1.22.7
iomesh/node-disk-exporter:1.8.0f03148764f38
stdlib@go1.14.7
1.22.7
iomesh/node-disk-manager:1.8.0002c4b92fd34
stdlib@go1.14.7
1.22.7
iomesh/node-disk-operator:1.8.0f6c76380db34
stdlib@go1.14.7
1.22.7
iomesh/operator:v1.1.060081c9b2f52
stdlib@go1.21.4
1.22.7
iomesh/post-delete-hook:v1.1.0eea5651f3270
stdlib@go1.21.4
1.22.7
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
stdlib@go1.19
1.22.7
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
stdlib@go1.19.7
1.22.7
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.22.7

Open the chart page →

49,004
IOMeshkubesphere-stable1.2.023 of 25See more

IOMesh kubesphere-stable 1.2.0

23 of the 25 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
stdlib@go1.21.5
1.22.7
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
stdlib@go1.21.5
1.22.7
iomesh/csi-driver:v2.8.01a151f602451
stdlib@go1.21.11
1.22.7
iomesh/csi-node-driver-registrar:v2.5.086f58b0a2106
stdlib@go1.17.3
1.22.7
iomesh/csi-provisioner:v3.0.0f9508460b273
stdlib@go1.16.2
1.22.7
iomesh/csi-snapshotter:v6.2.2becc53e25b96
stdlib@go1.19
1.22.7
iomesh/deck:v0.2.0282d6c419ed3
stdlib@go1.22.6
1.22.7
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
stdlib@go1.22.6
1.22.7
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
stdlib@go1.13.1
1.22.7
iomesh/livenessprobe:v2.8.0560f01510f99
stdlib@go1.18
1.22.7
iomesh/localpv-manager:v0.2.0f13deacac3f4
stdlib@go1.20.3
1.22.7
iomesh/node-disk-exporter:1.8.0f03148764f38
stdlib@go1.14.7
1.22.7
iomesh/node-disk-manager:1.8.0-2292ad270082e
stdlib@go1.14.7
1.22.7
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
stdlib@go1.14.7
1.22.7
iomesh/operator:v1.2.0ba4dd6be7e59
stdlib@go1.21.4
1.22.7
iomesh/post-delete-hook:v1.2.0e3b92f838f4b
stdlib@go1.21.4
1.22.7
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
stdlib@go1.19
1.22.7
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
stdlib@go1.19.7
1.22.7
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
stdlib@go1.20.3
1.22.7
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
stdlib@go1.20.3
1.22.7

Open the chart page →

46,692
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
stdlib@go1.13.10
1.22.7
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
stdlib@go1.15.6
1.22.7

Open the chart page →

14,457
aws-fsx-csi-driverkubesphere-testVerified publisher0.1.01 of 4See more

aws-fsx-csi-driver kubesphere-test 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
amazon/aws-fsx-csi-driver:latestc9b14856fd22
stdlib@go1.16.8
1.22.7

Open the chart page →

1,595
ccm-qingcloudkubesphere-testVerified publisher0.1.01 of 1See more

ccm-qingcloud kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
stdlib@go1.18.2
1.22.7

Open the chart page →

1,540
cni-hostnickubesphere-testVerified publisher0.1.01 of 1See more

cni-hostnic kubesphere-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
stdlib@go1.16.3
1.22.7

Open the chart page →

2,444
csi-neonsankubesphere-testVerified publisher1.3.06 of 6See more

csi-neonsan kubesphere-test 1.3.0

6 of the 6 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
stdlib@go1.16
1.22.7
csiplugin/csi-neonsan:v1.2.21fa83d45417f
stdlib@go1.14.4
1.22.7
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
stdlib@go1.16
1.22.7
csiplugin/csi-resizer:v1.2.036c31f7e1f43
stdlib@go1.16
1.22.7
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
stdlib@go1.15
1.22.7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.22.7

Open the chart page →

18,537
csi-qingcloudkubesphere-testVerified publisher1.4.06 of 6See more

csi-qingcloud kubesphere-test 1.4.0

6 of the 6 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
stdlib@go1.16
1.22.7
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
stdlib@go1.16
1.22.7
csiplugin/csi-qingcloud:v1.4.00766163dc046
stdlib@go1.19.13
1.22.7
csiplugin/csi-resizer:v1.2.036c31f7e1f43
stdlib@go1.16
1.22.7
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
stdlib@go1.15
1.22.7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.22.7

Open the chart page →

12,446
curvefs-csikubesphere-testVerified publisher0.1.01 of 3See more

curvefs-csi kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.22.7

Open the chart page →

2,831
mongodbkubesphere-testVerified publisher0.3.21 of 2See more

mongodb kubesphere-test 0.3.2

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
mikefarah/yq:2.4.16fc625c402de
stdlib@go1.13.3
1.22.7

Open the chart page →

9,640
online-boutiquekubesphere-testVerified publisher0.1.08 of 11See more

online-boutique kubesphere-test 0.1.0

8 of the 11 container images this version deploys carry CVE-2024-34156.

Open the chart page →

26,079
openelbkubesphere-testVerified publisher0.2.42 of 2See more

openelb kubesphere-test 0.2.4

2 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
stdlib@go1.15.15
1.22.7
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
stdlib@go1.16.9
1.22.7

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
stdlib@go1.15.15
1.22.7

Open the chart page →

2,791
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
stdlib@go1.15
1.22.7

Open the chart page →

2,220
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
stdlib@go1.20.4
1.22.7

Open the chart page →

4,458
kubestellar-uikubestellaruiVerified publisher0.1.12 of 4See more

kubestellar-ui kubestellarui 0.1.1

2 of the 4 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.22.7
mavrick1/kubestellar-b:latest45ca0429a1d4
stdlib@go1.20.3
1.22.7

Open the chart page →

4,778
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.22.7

Open the chart page →

8,795
kube-workload-restarterkube-workload-restarterVerified publisher0.0.41 of 1See more

kube-workload-restarter kube-workload-restarter 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
andreacioni/kube-workload-restarter:0.0.242938b310090a
stdlib@go1.20.2
1.22.7

Open the chart page →

1,815
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.42 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

2 of the 9 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.22.7
ghcr.io/kubiyabot/tool-manager:0.5.80cca6760763a
stdlib@go1.21.5
1.22.7

Open the chart page →

20,435
ctrlmeshkusionstackVerified publisher0.2.01 of 1See more

ctrlmesh kusionstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
stdlib@go1.20.14
1.22.7

Open the chart page →

3,477
operatingkusionstackVerified publisher0.5.11 of 1See more

operating kusionstack 0.5.1

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kusionstack/operating:v0.5.0c28bd96b986b
stdlib@go1.19.13
1.22.7

Open the chart page →

1,881
sample-operatorkusionstackVerified publisher0.1.21 of 1See more

sample-operator kusionstack 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
chaerr/kridge:demo-operator-v0.1.266833deec017
stdlib@go1.20.7
1.22.7

Open the chart page →

2,511
dynatrace-operatorkvalitetsitVerified publisher1.3.01 of 1See more

dynatrace-operator kvalitetsit 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
stdlib@go1.22.5
1.22.7

Open the chart page →

1,320
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
stdlib@go1.14.1
1.22.7

Open the chart page →

16,561
metadockvalitetsitVerified publisher0.0.72 of 2See more

metadoc kvalitetsit 0.0.7

2 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-app:maine89e351733ad
stdlib@go1.19.5
1.22.7
kvalitetsit/metadoc-web:mainf57e7553f5bd
stdlib@go1.16
1.22.7

Open the chart page →

4,033
nsp-prometheus-exporterkvalitetsitVerified publisher1.0.191 of 2See more

nsp-prometheus-exporter kvalitetsit 1.0.19

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
stdlib@go1.15.3
1.22.7

Open the chart page →

2,064
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
stdlib@go1.19.3
1.22.7

Open the chart page →

7,857
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
stdlib@go1.13.10
1.22.7

Open the chart page →

8,544
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
stdlib@go1.22.2
1.22.7

Open the chart page →

5,333
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
stdlib@go1.14
1.22.7

Open the chart page →

26,400
lagoon-docker-hostlagoon-chartsVerified publisher0.7.01 of 1See more

lagoon-docker-host lagoon-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
stdlib@go1.21.3
1.22.7

Open the chart page →

2,125
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
stdlib@go1.20.14
1.22.7

Open the chart page →

1,385
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.22.7

Open the chart page →

33,613
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
stdlib@go1.16.5
1.22.7
quay.io/metallb/speaker:v0.10.258cb99053bb3
stdlib@go1.16.5
1.22.7

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.55 of 6See more

prometheus lectures-k8sinfra 15.8.5

5 of the 6 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.22.7
prom/pushgateway:v1.4.2a684e7c830a4
stdlib@go1.16.9
1.22.7
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
stdlib@go1.16.7
1.22.7
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
stdlib@go1.17.3
1.22.7
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
stdlib@go1.18.4
1.22.7

Open the chart page →

9,100

Container images carrying it

2,781 by charts deploying them

A fixed version is listed for 9 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
stdlib@go1.13.10
1.22.7
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
stdlib@go1.19.13
1.22.7
1
polyaxon/training-operator:2.1.0b5b29deaec9a
stdlib@go1.20.13
1.22.7
1
pomerium/pomerium:v0.22.19c69b10a2126
stdlib@go1.20.3
1.22.7
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
stdlib@go1.19.4
1.22.7
1
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.22.7
1
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.22.7
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
stdlib@go1.13.12
1.22.7
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
stdlib@go1.16.9
1.22.7
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
stdlib@go1.19.7
1.22.7
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.22.7
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
stdlib@go1.22.6
1.22.7
1
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
stdlib@go1.19.3
1.22.7
1
prom/blackbox-exporter:v0.22.0608acee5704a
stdlib@go1.18.5
1.22.7
1
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
stdlib@go1.22.2
1.22.7
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
stdlib@go1.19.3
1.22.7
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.22.7
1
prom/influxdb-exporter:v0.11.427e33e18634a
stdlib@go1.19.9
1.22.7
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.22.7
1
prom/memcached-exporter:v0.9.001267317c95d
stdlib@go1.16.2
1.22.7
1
prom/node-exporter:v1.6.0d2e48098c364
stdlib@go1.20.4
1.22.7
1
prom/prometheus:v2.51.24f6c47e39a90
stdlib@go1.22.2
1.22.7
1
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.22.7
1
prom/prometheus:v2.48.0b440bc0e8aa5
stdlib@go1.21.4
1.22.7
1
prom/prometheus:v2.19.2cd134bd4fca0
stdlib@go1.14.4
1.22.7
1
prom/prometheus:v2.16.0e4ca62c0d62f
stdlib@go1.13.8
1.22.7
1
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.22.7
1
prom/pushgateway:v1.5.128fe26c8b8b1
stdlib@go1.19.3
1.22.7
1
prom/pushgateway:v1.4.33496e0f85943
stdlib@go1.18.2
1.22.7
1
prom/snmp-exporter:v0.20.09d226d7de223
stdlib@go1.15.8
1.22.7
1
prom/statsd-exporter:v0.24.061d866e93b56
stdlib@go1.19.9
1.22.7
1
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.22.7
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
stdlib@go1.22.6
1.22.7
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
stdlib@go1.21.5
1.22.7
1
pschiffe/pdns-mysql:alpined196c796cafb
stdlib@go1.21.5
1.22.7
1
pschiffe/pdns-pgsql:5.0a227d41bc665
stdlib@go1.21.5
1.22.7
1
pysga1996/redis:latest3af6d0c7db19
stdlib@go1.18.2
1.22.7
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
stdlib@go1.18.2
1.22.7
1
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.22.7
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
stdlib@go1.15.5
1.22.7
1
quiq/docker-registry-ui:0.9.491281da47036
stdlib@go1.18
1.22.7
1
qumine/ingress-controller:v0.8.5f2c8a2148381
stdlib@go1.19
1.22.7
1
qumine/minecraft-server:v0.1.15c0b650d51132
stdlib@go1.19.4
1.22.7
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
stdlib@go1.17
1.22.7
1
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
stdlib@go1.20.11
1.22.7
1
ralexstokes/eth2-fork-mon:latestc0d4bbefd31f
stdlib@go1.16.7
1.22.7
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
stdlib@go1.20.8
1.22.7
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
stdlib@go1.19.2
1.22.7
1
rancher/kubectl:v1.25.085a0d1148784
stdlib@go1.19
1.22.7
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
stdlib@go1.16.6
1.22.7
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.