CVE-2024-3566
CriticalAdvisory
Published 18 Jun 2025In the index since 22 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.069
- 94th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,828 indexed, latest versions
- Container images
- 8
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Command injection vulnerability in programing languages on Microsoft Windows operating system.
Carried by container images the latest versions of 8 of 17,828 indexed charts deploy, on 8 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nodebitnami | 18.4.0-0, 18.7.0-1, 18.12.1-0, 18.13.0-0 | 18.19.0 | 8 |
- OSV records
- BIT-node-2024-3566
- Also known as
- BIT-node-min-2024-3566, HSEC-2024-0003
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| apikrateo | 1.0.3 | 1 of 1See more | 4,346 |
| argocd-servicekrateo | 1.0.7 | 1 of 1See more | 4,391 |
| capi-servicekrateo | 1.1.9 | 1 of 1See more | 4,117 |
| codequality-servicekrateo | 1.1.1 | 1 of 1See more | 3,979 |
| component-servicekrateo | 0.2.1 | 1 of 1See more | 4,308 |
| endpoint-servicekrateo | 1.0.1 | 1 of 1See more | 4,875 |
| keptn-service-insielkrateo | 0.1.3 | 1 of 1See more | 4,271 |
| log-servicekrateo | 1.0.0 | 1 of 1See more | 4,577 |
Container images carrying it
8 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | edbaa031754d | node | 18.19.0 | 1 |
| ghcr.io/ | 49b727854938 | node | 18.19.0 | 1 |
| ghcr.io/ | 2eee721260eb | node | 18.19.0 | 1 |
| ghcr.io/ | 9a9a77b01eb1 | node | 18.19.0 | 1 |
| ghcr.io/ | 4a5f506c0560 | node | 18.19.0 | 1 |
| ghcr.io/ | 6c3777c042f7 | node | 18.19.0 | 1 |
| ghcr.io/ | c1d475bb7f06 | node | 18.19.0 | 1 |
| ghcr.io/ | b431a8154be0 | node | 18.19.0 | 1 |