StackRadar

CVE-2024-34156

High

Advisory

Published 6 Sept 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,479
of 17,844 indexed, latest versions
Container images
2,905
deployed by those charts
Fix available
9 of 10
affected packages

Red Hat Security Advisory: skopeo security update

Carried by container images the latest versions of 2,479 of 17,844 indexed charts deploy, on 2,905 images.

Affected packageAffected versionsFixed inImages
skopeorpm2:1.11.2-0.1.el9, 2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.11.2-0.3.module+el8.8.0+22332+2132e5c3, 2:1.16.1-2.el9_52
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-66.module+el8.8.0+22332+2132e5c31
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.15-4.module+el8.8.0+22332+2132e5c31
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.11-1.module+el8.8.0+22332+2132e5c31
git-lfsrpm2.13.3-3.el8_60:3.4.1-3.el8_101
golang-1.19deb1.19.8-2no fix listed1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-1.module+el8.8.0+22332+2132e5c31
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.8.0+22332+2132e5c31
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.0-3.module+el8.8.0+22332+2132e5c31
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+137 more1.22.72,905
OSV records
DEBIAN-CVE-2024-34156RHSA-2024:11217RHSA-2024:7135RHSA-2024:7769GO-2024-3106
Also known as
BIT-golang-2024-34156, RHSA-2024:7455, RHSA-2024:7821, RHSA-2024:8111

Charts affected

2,479 by stars
ChartLatestAffected imagesRadar Score
servereoloserverVerified publisher0.1.03 of 7See more

server eoloserver 0.1.0

3 of the 7 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.22.7
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.22.7
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.22.7

Open the chart page →

33,408
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
stdlib@go1.21.10
1.22.7

Open the chart page →

994
postgresql-backupeosc-lot-1Verified publisher0.4.21 of 2See more

postgresql-backup eosc-lot-1 0.4.2

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine3.20468d34fefd63
stdlib@go1.18.2
1.22.7

Open the chart page →

1,492
rabbitmqeosc-lot-1Verified publisher0.3.01 of 2See more

rabbitmq eosc-lot-1 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-managemente582c0bc7766
stdlib@go1.22.2
1.22.7

Open the chart page →

2,719
rabbitmq-usereosc-lot-1Verified publisher0.1.01 of 1See more

rabbitmq-user eosc-lot-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
stdlib@go1.21.10
1.22.7

Open the chart page →

972
rsyslogeosc-lot-1Verified publisher0.2.11 of 2See more

rsyslog eosc-lot-1 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/logrotate:3-alpineb0e20d200f89
stdlib@go1.22.4
1.22.7

Open the chart page →

414
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
stdlib@go1.20
1.22.7

Open the chart page →

1,691
upgrade-responderepinioVerified publisher0.2.02 of 5See more

upgrade-responder epinio 0.2.0

2 of the 5 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
stdlib@go1.20.10
1.22.7
longhornio/upgrade-responder:v0.2.05875cef29348
stdlib@go1.17.13
1.22.7

Open the chart page →

7,577
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
stdlib@go1.19.6
1.22.7
epamedp/edp-admin-console:2.14.0616c678ba3e7
stdlib@go1.18.3
1.22.7

Open the chart page →

4,303
edp-argocd-operatorepmdedpVerified publisher0.2.01 of 1See more

edp-argocd-operator epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/edp-argocd-operator:0.2.0976a662a5e72
stdlib@go1.18.4
1.22.7

Open the chart page →

1,570
edp-headlampepmdedpVerified publisher0.25.01 of 1See more

edp-headlamp epmdedp 0.25.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/edp-headlamp:0.25.093417e18bb1a
stdlib@go1.21.13
1.22.7

Open the chart page →

1,256
edp-tekton-interceptorepmdedpVerified publisher0.2.41 of 1See more

edp-tekton-interceptor epmdedp 0.2.4

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.2.4924939850655
stdlib@go1.18.3
1.22.7

Open the chart page →

1,360
jenkins-operatorepmdedpVerified publisher2.15.31 of 3See more

jenkins-operator epmdedp 2.15.3

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.15.328ef56bc0ca3
stdlib@go1.20.11
1.22.7

Open the chart page →

2,111
perf-operatorepmdedpVerified publisher2.13.01 of 1See more

perf-operator epmdedp 2.13.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/perf-operator:2.13.0bd2079b7bfcb
stdlib@go1.19.6
1.22.7

Open the chart page →

1,117
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
stdlib@go1.18.4
1.22.7

Open the chart page →

2,184
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
stdlib@go1.17.2
1.22.7

Open the chart page →

2,831
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
stdlib@go1.17.2
1.22.7

Open the chart page →

2,818
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
stdlib@go1.17.2
1.22.7

Open the chart page →

2,264
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
stdlib@go1.17.2
1.22.7

Open the chart page →

2,231
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.22.7

Open the chart page →

7,969
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
stdlib@go1.16.7
1.22.7

Open the chart page →

7,969
escvmschedulerescvmscheduler1.0.71 of 3See more

escvmscheduler escvmscheduler 1.0.7

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.22.7

Open the chart page →

5,154
armiarmaethereum-helm-chartsVerified publisher0.1.21 of 2See more

armiarma ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethpandaops/armiarma:master1a9c3264f0a9
stdlib@go1.21.8
1.22.7

Open the chart page →

1,160
blob-me-babyethereum-helm-chartsVerified publisher0.1.21 of 1See more

blob-me-baby ethereum-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethpandaops/blob-me-baby:latestad26158420dd
stdlib@go1.20.1
1.22.7

Open the chart page →

1,457
chaos-meshethereum-helm-chartsVerified publisher0.0.32 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

2 of the 4 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
stdlib@go1.19.7
1.22.7
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
stdlib@go1.16.2
1.22.7

Open the chart page →

12,778
dugtrioethereum-helm-chartsVerified publisher0.0.71 of 1See more

dugtrio ethereum-helm-charts 0.0.7

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethpandaops/dugtrio:1.0.0e261d1734e9f
stdlib@go1.21.4
1.22.7

Open the chart page →

1,141
eth2-fork-monethereum-helm-chartsVerified publisher0.1.31 of 1See more

eth2-fork-mon ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ralexstokes/eth2-fork-mon:latestc0d4bbefd31f
stdlib@go1.16.7
1.22.7

Open the chart page →

1,958
ethereum-validator-metrics-exporterethereum-helm-chartsVerified publisher0.0.11 of 1See more

ethereum-validator-metrics-exporter ethereum-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethpandaops/ethereum-validator-metrics-exporter:latest38448e9d4aef
stdlib@go1.19.10
1.22.7

Open the chart page →

635
eth-faucetethereum-helm-chartsVerified publisher0.1.11 of 1See more

eth-faucet ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
chainflag/eth-faucet:latestac642796bcb6
stdlib@go1.17.13
1.22.7

Open the chart page →

2,010
forkmonethereum-helm-chartsVerified publisher0.1.61 of 1See more

forkmon ethereum-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
holiman/nodemonitor:latest5cd609761065
stdlib@go1.20.3
1.22.7

Open the chart page →

1,693
stubbiesethereum-helm-chartsVerified publisher0.0.21 of 1See more

stubbies ethereum-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethpandaops/stubbies:latest9f1d6aec0d04
stdlib@go1.19.8
1.22.7

Open the chart page →

685
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
stdlib@go1.17.2
1.22.7

Open the chart page →

2,714
ethexporterethersphereVerified publisher0.3.01 of 1See more

ethexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
darkobas/ethexporter:latest62e6464491ba
stdlib@go1.19.1
1.22.7

Open the chart page →

2,827
ethproxyethersphereVerified publisher0.2.01 of 1See more

ethproxy ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethersphere/ethproxy:latest3a8a3926caa2
stdlib@go1.18.7
1.22.7

Open the chart page →

1,403
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.186d6d12a40465
stdlib@go1.18.2
1.22.7

Open the chart page →

4,808
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.22.7

Open the chart page →

3,348
tokenexporterethersphereVerified publisher0.3.01 of 1See more

tokenexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
darkobas/tokenexporter:latesta0349a0eedf0
stdlib@go1.19.1
1.22.7

Open the chart page →

2,827
whatsmyipeugen1.3.21 of 1See more

whatsmyip eugen 1.3.2

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
ghcr.io/eugenmayer/whatsmyip:0.0.14b6700cc0e2d
stdlib@go1.22.1
1.22.7

Open the chart page →

474
domain_exporterevilgn0me0.1.41 of 1See more

domain_exporter evilgn0me 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
caarlos0/domain_exporter:v1.23.0d11dec138900
stdlib@go1.21.6
1.22.7

Open the chart page →

1,272
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
stdlib@go1.18.1
1.22.7

Open the chart page →

21,477
pgbouncerevilmartians0.2.01 of 2See more

pgbouncer evilmartians 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.22.7

Open the chart page →

1,839
preview-appsevilmartians0.4.01 of 1See more

preview-apps evilmartians 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
stdlib@go1.20.14
1.22.7

Open the chart page →

628
cloudflaredewatkinsVerified publisher0.1.01 of 1See more

cloudflared ewatkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2024.11.1665dda65335e
stdlib@go1.22.5-devel-cf
1.22.7

Open the chart page →

1,260
exa-csiexa-csi-driver0.2.0-rev26 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

6 of the 6 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
stdlib@go1.23.0
1.22.7
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
stdlib@go1.21.5
1.22.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
stdlib@go1.21.5
1.22.7
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
stdlib@go1.21.5
1.22.7
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.22.7
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.22.7

Open the chart page →

7,136
exchange-hackexchange-hack0.1.01 of 1See more

exchange-hack exchange-hack 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
oranhack7/solidproject:77c6453942223f
stdlib@go1.21.7
1.22.7

Open the chart page →

818
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.02 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
stdlib@go1.21.3
1.22.7
grafana/loki-canary:2.9.6549a40203e97
stdlib@go1.21.3
1.22.7

Open the chart page →

5,946
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
stdlib@go1.17.1
1.22.7

Open the chart page →

7,554
degafactlyVerified publisher0.11.132 of 3See more

dega factly 0.11.13

2 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.22.7
factly/dega-server:0.15.194d21479382e
stdlib@go1.16.2
1.22.7

Open the chart page →

5,748
kavachfactlyVerified publisher0.9.51 of 2See more

kavach factly 0.9.5

1 of the 2 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
factly/kavach-server:0.22.3be85ff1b9bd3
stdlib@go1.16.2
1.22.7

Open the chart page →

3,583
mandefactlyVerified publisher0.5.181 of 3See more

mande factly 0.5.18

1 of the 3 container images this version deploys carry CVE-2024-34156.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
stdlib@go1.18.10
1.22.7

Open the chart page →

4,778

Container images carrying it

2,905 by charts deploying them

A fixed version is listed for 9 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.22.7
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.22.7
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.