StackRadar

CVE-2024-38999

Critical

Advisory

Published 1 Jul 2024In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
10.0
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

jrburke requirejs vulnerable to prototype pollution

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
requirejsnpm2.3.5, 2.3.62.3.716
OSV records
GHSA-x3m3-4wpv-5vgc

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
requirejs@2.3.6
2.3.7
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
requirejs@2.3.6
2.3.7

Open the chart page →

52,919
daskhubdask2024.1.12 of 9See more

daskhub dask 2024.1.1

2 of the 9 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
requirejs@2.3.6
2.3.7
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
requirejs@2.3.6
2.3.7

Open the chart page →

14,094
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
requirejs@2.3.6
2.3.7

Open the chart page →

29,901
jupyterhubd4nVerified publisher3.3.72 of 7See more

jupyterhub d4n 3.3.7

2 of the 7 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
requirejs@2.3.6
2.3.7
aristidetm/k8s-hub:3.3.7ccb516cb8474
requirejs@2.3.6
2.3.7

Open the chart page →

16,604
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
requirejs@2.3.5
2.3.7

Open the chart page →

57,669
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
requirejs@2.3.6
2.3.7

Open the chart page →

37,671
jupyterhubkubeblocksVerified publisher0.1.02 of 7See more

jupyterhub kubeblocks 0.1.0

2 of the 7 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
requirejs@2.3.6
2.3.7
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
requirejs@2.3.6
2.3.7

Open the chart page →

7,356
nubladolsst-sqre0.9.233 of 5See more

nublado lsst-sqre 0.9.23

3 of the 5 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
lsstsqre/prepuller:latest19c2dfc4e4ff
requirejs@2.3.6
2.3.7
lsstsqre/sciplat-hub:latest5e0ade6bed1c
requirejs@2.3.6
2.3.7
lsstsqre/wfdispatcher:lateste9feb99f524d
requirejs@2.3.6
2.3.7

Open the chart page →

5,786
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
requirejs@2.3.6
2.3.7

Open the chart page →

17,779
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2024-38999.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
requirejs@2.3.6
2.3.7

Open the chart page →

8,607

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aristidetm/basic-notebook:3.6.5469dbc951224
requirejs@2.3.6
2.3.7
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
requirejs@2.3.6
2.3.7
1
daskdev/dask-notebook:1.1.0052630f5ca04
requirejs@2.3.6
2.3.7
1
ibmcom/microclimate-theia:lateste17bdccc5030
requirejs@2.3.5
2.3.7
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
requirejs@2.3.6
2.3.7
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
requirejs@2.3.6
2.3.7
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
requirejs@2.3.6
2.3.7
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
requirejs@2.3.6
2.3.7
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
requirejs@2.3.6
2.3.7
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
requirejs@2.3.6
2.3.7
1
lsstsqre/prepuller:latest19c2dfc4e4ff
requirejs@2.3.6
2.3.7
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
requirejs@2.3.6
2.3.7
1
lsstsqre/wfdispatcher:lateste9feb99f524d
requirejs@2.3.6
2.3.7
1
pangeo/base-notebook:2024.01.155fbe688a4f80
requirejs@2.3.6
2.3.7
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
requirejs@2.3.6
2.3.7
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
requirejs@2.3.6
2.3.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.