StackRadar

CVE-2024-3727

High

Advisory

Published 14 May 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 2
affected packages

github.com/containers/image allows unexpected authenticated registry accesses

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
github.com/containers/image/v5golangv5.9.0, v5.10.2, v5.15.0, v5.19.0+6 more5.29.315
golang-github-containers-imagedeb5.23.1-4no fix listed1
OSV records
DEBIAN-CVE-2024-3727GHSA-6wvf-f2vw-3425
Also known as
GO-2024-2842

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
github.com/containers/image/v5@v5.29.1
5.29.3

Open the chart page →

1,981
agentareaagentareaVerified publisher0.0.181 of 16See more

agentarea agentarea 0.0.18

1 of the 16 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
agentarea/agentarea-mcp-runner:latestd3c209a5d531
golang-github-containers-image@5.23.1-4
no fix listed

Open the chart page →

14,914
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
github.com/containers/image/v5@v5.21.1
5.29.3

Open the chart page →

2,969
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/containers/image/v5@v5.25.0
5.29.3

Open the chart page →

3,274
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
artifacthub/tracker:v1.19.06596c8c4d955
github.com/containers/image/v5@v5.29.0
5.29.3

Open the chart page →

14,491
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/containers/image/v5@v5.15.0
5.29.3

Open the chart page →

25,151
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/containers/image/v5@v5.15.0
5.29.3

Open the chart page →

6,921
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/containers/image/v5@v5.26.2
5.29.3

Open the chart page →

1,736
dregsyhelm-charts-nr0.1.51 of 1See more

dregsy helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
github.com/containers/image/v5@v5.21.1
5.29.3

Open the chart page →

2,969
kubeclaritykubeclarity2.23.31 of 5See more

kubeclarity kubeclarity 2.23.3

1 of the 5 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/containers/image/v5@v5.19.0
5.29.3

Open the chart page →

5,496
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
github.com/containers/image/v5@v5.9.0
5.29.3

Open the chart page →

18,023
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/containers/image/v5@v5.15.0
5.29.3

Open the chart page →

8,599
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/containers/image/v5@v5.10.2
5.29.3

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/containers/image/v5@v5.10.2
5.29.3

Open the chart page →

15,466
pixie-operator-chartpixie0.1.71 of 3See more

pixie-operator-chart pixie 0.1.7

1 of the 3 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned1b6002156f56
github.com/containers/image/v5@v5.28.0
5.29.3

Open the chart page →

1,899
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/containers/image/v5@v5.29.0
5.29.3

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/containers/image/v5@v5.10.2
5.29.3

Open the chart page →

29,227
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-3727.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/containers/image/v5@v5.10.2
5.29.3

Open the chart page →

28,165

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
xelalex/dregsy:0.4.3574054e1c417
github.com/containers/image/v5@v5.21.1
5.29.3
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/containers/image/v5@v5.10.2
5.29.3
2
agentarea/agentarea-mcp-runner:latestd3c209a5d531
golang-github-containers-image@5.23.1-4
no fix listed
1
anchore/anchore-engine:v0.10.0bde9eedf639d
github.com/containers/image/v5@v5.9.0
5.29.3
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/containers/image/v5@v5.29.0
5.29.3
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/containers/image/v5@v5.25.0
5.29.3
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
github.com/containers/image/v5@v5.29.1
5.29.3
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/containers/image/v5@v5.19.0
5.29.3
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/containers/image/v5@v5.15.0
5.29.3
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/containers/image/v5@v5.15.0
5.29.3
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/containers/image/v5@v5.10.2
5.29.3
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/containers/image/v5@v5.29.0
5.29.3
1
quay.io/operator-framework/olm1b6002156f56
github.com/containers/image/v5@v5.28.0
5.29.3
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/containers/image/v5@v5.15.0
5.29.3
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/containers/image/v5@v5.10.2
5.29.3
1
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/containers/image/v5@v5.26.2
5.29.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.