StackRadar

CVE-2024-36124

Medium

Advisory

Published 4 Jun 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash

Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
snappymaven0.2, 0.3, 0.40.518
OSV records
GHSA-8wh2-6qhj-h7j9

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
metabasedeliveryheroVerified publisher0.14.41 of 1See more

metabase deliveryhero 0.14.4

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
snappy@0.4
0.5

Open the chart page →

2,572
sparkmicrosoft1.0.41 of 3See more

spark microsoft 1.0.4

1 of the 3 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
snappy@0.2
0.5

Open the chart page →

13,738
puppetserverpuppetserver9.5.21 of 5See more

puppetserver puppetserver 9.5.2

1 of the 5 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
snappy@0.4
0.5

Open the chart page →

14,184
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
snappy@0.4
0.5

Open the chart page →

2,221
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
snappy@0.4
0.5

Open the chart page →

14,728
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
snappy@0.4
0.5

Open the chart page →

4,601
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
snappy@0.3
0.5

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
snappy@0.4
0.5

Open the chart page →

6,497
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
snappy@0.2
0.5

Open the chart page →

14,066
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
snappy@0.2
0.5

Open the chart page →

6,147
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
snappy@0.2
0.5

Open the chart page →

5,639
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
snappy@0.2
0.5

Open the chart page →

6,147
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
snappy@0.4
0.5

Open the chart page →

2,572
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
snappy@0.4
0.5
ibmcom/microclimate-theia:lateste17bdccc5030
snappy@0.4
0.5

Open the chart page →

57,669
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
snappy@0.4
0.5

Open the chart page →

1,628
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
snappy@0.4
0.5

Open the chart page →

5,826
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
snappy@0.3
0.5

Open the chart page →

21,211
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
snappy@0.3
0.5

Open the chart page →

13,767
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2024-36124.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
snappy@0.3
0.5

Open the chart page →

9,397

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gradiant/spark:2.4.4-python-alpine97657d56e927
snappy@0.2
0.5
2
metabase/metabase:v0.45.21fb334ce4820
snappy@0.4
0.5
2
apache/drill:1.21.11f96558fd292
snappy@0.3
0.5
1
assistiot/automated_configuration:latest23f195a7a26a
snappy@0.4
0.5
1
bivas/presto:0.19605545994f806
snappy@0.3
0.5
1
dbanda/livy:0.80ca125e68e53
snappy@0.2
0.5
1
duck1123/dinsro:latest9568c5961d5d
snappy@0.4
0.5
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
snappy@0.4
0.5
1
ibmcom/microclimate-theia:lateste17bdccc5030
snappy@0.4
0.5
1
lightbend/spark-history-server:2.4.00bedf37f428a
snappy@0.2
0.5
1
metabase/metabase:v0.46.09ebdc664a6b2
snappy@0.4
0.5
1
metabase/metabase:v0.31.2ffb2dccacefc
snappy@0.4
0.5
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
snappy@0.4
0.5
1
raykrueger/riemann:0.2.14c8baf3de57bb
snappy@0.4
0.5
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
snappy@0.2
0.5
1
trinodb/trino:45038c6f24ab1a4
snappy@0.3
0.5
1
trinodb/trino:405ee80ab5eeab2
snappy@0.3
0.5
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
snappy@0.4
0.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.