StackRadar

CVE-2024-38476

Critical

Advisory

Published 1 Jul 2024In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.416
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
28
deployed by those charts
Fix available
4 of 4
affected packages

Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 28 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+3 more2.4.41-4ubuntu3.19, 2.4.52-1ubuntu4.10, 2.4.61-1~deb12u118
apache2apk2.4.54-r1, 2.4.57-r3, 2.4.58-r0, 2.4.59-r02.4.60-r05
apachebitnami2.4.54-1572.4.601
httpdrpm2.4.37-43.module+el8.5.0+13806+b30d9eec.1, 2.4.37-56.module+el8.8.0+18758+b3a9c8da.6, 2.4.57-8.el9, 2.4.57-11.el9_40:2.4.37-65.module+el8.10.0+22196+d82931da.2, 0:2.4.57-11.el9_4.14
OSV records
ALPINE-CVE-2024-38476BIT-apache-2024-38476DEBIAN-CVE-2024-38476RHSA-2024:5138RHSA-2024:5193UBUNTU-CVE-2024-38476
Also known as
RHSA-2024:6136, USN-6885-1, USN-6885-2, USN-8338-1

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19

Open the chart page →

18,509
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
httpd@2.4.57-11.el9_4
0:2.4.57-11.el9_4.1

Open the chart page →

7,450
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
apache2@2.4.59-1~deb12u1
2.4.61-1~deb12u1

Open the chart page →

18,376
organizrgeek-cookbookVerified publisher7.4.21 of 1See more

organizr geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
organizr/organizr:latest1ce319d73cdf
apache2@2.4.58-r0
2.4.60-r0

Open the chart page →

1,533
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.19
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.19

Open the chart page →

22,568
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
httpd@2.4.37-56.module+el8.8.0+18758+b3a9c8da.6
0:2.4.37-65.module+el8.10.0+22196+d82931da.2

Open the chart page →

25,151
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
apache2@2.4.57-2
2.4.61-1~deb12u1

Open the chart page →

7,141
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.60

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.60

Open the chart page →

7,541
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.19

Open the chart page →

20,933
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19

Open the chart page →

14,659
rtorrent-rutorrentgeek-cookbookVerified publisher1.1.21 of 1See more

rtorrent-rutorrent geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
apache2@2.4.54-r1
2.4.60-r0

Open the chart page →

4,232
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.10

Open the chart page →

14,290
organizrk8s-home-lab-repo8.1.11 of 1See more

organizr k8s-home-lab-repo 8.1.1

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
organizr/organizr:latest1ce319d73cdf
apache2@2.4.58-r0
2.4.60-r0

Open the chart page →

1,533
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
2.4.61-1~deb12u1

Open the chart page →

8,860
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19

Open the chart page →

10,248
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
apache2@2.4.59-r0
2.4.60-r0

Open the chart page →

5,332
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
2.4.61-1~deb12u1

Open the chart page →

12,813
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19

Open the chart page →

22,658
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
httpd@2.4.57-8.el9
0:2.4.57-11.el9_4.1

Open the chart page →

18,922
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19

Open the chart page →

9,167
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
apache2@2.4.57-r3
2.4.60-r0

Open the chart page →

4,215
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
apache2@2.4.57-r3
2.4.60-r0

Open the chart page →

2,449
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
2.4.61-1~deb12u1

Open the chart page →

13,510
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.19

Open the chart page →

30,687
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-65.module+el8.10.0+22196+d82931da.2

Open the chart page →

6,671
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
2.4.61-1~deb12u1

Open the chart page →

9,102
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
2.4.41-4ubuntu3.19

Open the chart page →

18,756
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2024-38476.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.61-1~deb12u1

Open the chart page →

10,001

Container images carrying it

28 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
organizr/organizr:latest1ce319d73cdf
apache2@2.4.58-r0
2.4.60-r0
2
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.60
2
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
2.4.61-1~deb12u1
1
codetogether/codetogether:latest4348c8a38752
httpd@2.4.57-11.el9_4
0:2.4.57-11.el9_4.1
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
apache2@2.4.54-r1
2.4.60-r0
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19
1
domainmod/domainmod:4.23.04017bfe4c597
apache2@2.4.57-2
2.4.61-1~deb12u1
1
dragonflyoss/client:v0.1.82edf3e921f4e0
apache2@2.4.59-1~deb12u1
2.4.61-1~deb12u1
1
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.61-1~deb12u1
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
2.4.61-1~deb12u1
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19
1
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
2.4.61-1~deb12u1
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
apache2@2.4.57-r3
2.4.60-r0
1
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19
1
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.10
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.19
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
apache2@2.4.41-4ubuntu3.14
2.4.41-4ubuntu3.19
1
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.19
1
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-65.module+el8.10.0+22196+d82931da.2
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
2.4.61-1~deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
2.4.41-4ubuntu3.19
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
apache2@2.4.59-r0
2.4.60-r0
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.19
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
apache2@2.4.57-r3
2.4.60-r0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.19
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
httpd@2.4.37-56.module+el8.8.0+18758+b3a9c8da.6
0:2.4.37-65.module+el8.10.0+22196+d82931da.2
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
httpd@2.4.57-8.el9
0:2.4.57-11.el9_4.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.