StackRadar

CVE-2024-35192

Medium

Advisory

Published 20 May 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Trivy possibly leaks registry credential when scanning images from malicious registries

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
github.com/aquasecurity/trivygolangv0.29.2, v0.32.0, v0.37.1, v0.43.1+6 more0.51.210
OSV records
GHSA-xcq4-m2r3-cmrj
Also known as
GO-2024-2870

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/aquasecurity/trivy@v0.46.0
0.51.2

Open the chart page →

2,898
trivy-operatordevopstalesVerified publisher2.5.01 of 1See more

trivy-operator devopstales 2.5.0

1 of the 1 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
devopstales/trivy-operator:2.575136aa7a26e
github.com/aquasecurity/trivy@v0.37.1
0.51.2

Open the chart page →

5,598
artifact-hubsoftonic1.19.02 of 8See more

artifact-hub softonic 1.19.0

2 of the 8 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
aquasec/trivy:0.43.1944a04445179
github.com/aquasecurity/trivy@v0.43.1
0.51.2
artifacthub/scanner:v1.19.0323d026e78c3
github.com/aquasecurity/trivy@v0.50.1
0.51.2

Open the chart page →

14,491
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.51.2

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.51.2

Open the chart page →

68,240
harborkubesphereVerified publisher1.9.31 of 11See more

harbor kubesphere 1.9.3

1 of the 11 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/aquasecurity/trivy@v0.29.2
0.51.2

Open the chart page →

17,798
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
github.com/aquasecurity/trivy@v0.32.0
0.51.2

Open the chart page →

4,271
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/aquasecurity/trivy@v0.48.3
0.51.2

Open the chart page →

9,774
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.51.2

Open the chart page →

68,240
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/aquasecurity/trivy@v0.44.0
0.51.2

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2024-35192.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/aquasecurity/trivy@v0.44.1
0.51.2

Open the chart page →

2,505

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/aquasecurity/trivy@v0.46.1
0.51.2
3
aquasec/trivy:0.43.1944a04445179
github.com/aquasecurity/trivy@v0.43.1
0.51.2
1
aquasec/trivy:0.32.0973d0df16189
github.com/aquasecurity/trivy@v0.32.0
0.51.2
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/aquasecurity/trivy@v0.50.1
0.51.2
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/aquasecurity/trivy@v0.37.1
0.51.2
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/aquasecurity/trivy@v0.29.2
0.51.2
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/aquasecurity/trivy@v0.44.0
0.51.2
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/aquasecurity/trivy@v0.44.1
0.51.2
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/aquasecurity/trivy@v0.46.0
0.51.2
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/aquasecurity/trivy@v0.48.3
0.51.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.