StackRadar

CVE-2024-39330

High

Advisory

Published 10 Jul 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Django Path Traversal vulnerability

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
djangopypi4.2, 4.2.7, 4.2.11, 5.0.3+1 more4.2.14, 5.0.78
OSV records
GHSA-9jmf-237g-qf46
Also known as
BIT-django-2024-39330, PYSEC-2024-58

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
netboxstartechnicaVerified publisher5.1.01 of 4See more

netbox startechnica 5.1.0

1 of the 4 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
django@4.2.11
4.2.14

Open the chart page →

1,650
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
django@4.2
4.2.14

Open the chart page →

2,236
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
django@5.0.4
5.0.7

Open the chart page →

2,233
ddosifyanteonVerified publisher1.7.51 of 13See more

ddosify anteon 1.7.5

1 of the 13 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
django@4.2.11
4.2.14

Open the chart page →

25,669
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
django@5.0.3
5.0.7

Open the chart page →

11,335
codecovdoubanVerified publisher0.2.42 of 8See more

codecov douban 0.2.4

2 of the 8 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
4.2.14
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
4.2.14

Open the chart page →

24,917
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2024-39330.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
4.2.14

Open the chart page →

16,384

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codecov/self-hosted-api:24.4.10475cb1c3136
django@4.2.7
4.2.14
1
codecov/self-hosted-worker:24.4.1837f546b479b
django@4.2.11
4.2.14
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
django@4.2.11
4.2.14
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
django@4.2
4.2.14
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
django@4.2.11
4.2.14
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
django@5.0.3
5.0.7
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
django@5.0.4
5.0.7
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
4.2.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.