StackRadar

CVE-2024-42353

Medium

Advisory

Published 14 Aug 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
23
deployed by those charts
Fix available
1 of 1
affected package

WebOb's location header normalization during redirect leads to open redirect

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 23 images.

Affected packageAffected versionsFixed inImages
webobpypi1.2.3, 1.4.1, 1.8.2, 1.8.5+1 more1.8.823
OSV records
GHSA-mg3v-6m49-jhp3
Also known as
PYSEC-2024-188

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
stackstorm-hastackstormVerified publisher1.1.011 of 17See more

stackstorm-ha stackstorm 1.1.0

11 of the 17 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
webob@1.8.7
1.8.8
stackstorm/st2api:3.86f56d239d280
webob@1.8.7
1.8.8
stackstorm/st2auth:3.833ecfda16608
webob@1.8.7
1.8.8
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
webob@1.8.7
1.8.8
stackstorm/st2notifier:3.8f190a6212195
webob@1.8.7
1.8.8
stackstorm/st2rulesengine:3.8259503496ff9
webob@1.8.7
1.8.8
stackstorm/st2scheduler:3.8b1de2055c362
webob@1.8.7
1.8.8
stackstorm/st2sensorcontainer:3.8b1a338f64773
webob@1.8.7
1.8.8
stackstorm/st2stream:3.81c8904a3bf67
webob@1.8.7
1.8.8
stackstorm/st2timersengine:3.81bf35bfaf00c
webob@1.8.7
1.8.8
stackstorm/st2workflowengine:3.819fdfffdbba8
webob@1.8.7
1.8.8

Open the chart page →

96,419
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
webob@1.8.5
1.8.8

Open the chart page →

24,930
radosgwananace-chartsVerified publisher0.3.41 of 1See more

radosgw ananace-charts 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
ceph/daemon:latest-nautilus90f30824a96e
webob@1.2.3
1.8.8

Open the chart page →

1,650
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
webob@1.8.7
1.8.8
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
webob@1.8.7
1.8.8

Open the chart page →

22,568
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
webob@1.8.5
1.8.8

Open the chart page →

1,382
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
webob@1.4.1
1.8.8

Open the chart page →

70,895
errbotmidokura-communityVerified publisher0.0.51 of 1See more

errbot midokura-community 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
errbotio/errbot:6.1.900ee4e0953ab
webob@1.8.7
1.8.8

Open the chart page →

2,233
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
webob@1.8.2
1.8.8

Open the chart page →

55,726
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
webob@1.8.2
1.8.8
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
webob@1.8.2
1.8.8

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
webob@1.8.2
1.8.8

Open the chart page →

26,211
syncstorageschichtelVerified publisher0.1.11 of 1See more

syncstorage schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
mozilla/syncstorage-rs:0.15.893752877dced
webob@1.8.7
1.8.8

Open the chart page →

1,318
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
webob@1.8.5
1.8.8

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2024-42353.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
webob@1.8.5
1.8.8

Open the chart page →

11,784

Container images carrying it

23 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
webob@1.8.2
1.8.8
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
webob@1.8.5
1.8.8
2
ceph/daemon:latest-nautilus90f30824a96e
webob@1.2.3
1.8.8
1
errbotio/errbot:6.1.900ee4e0953ab
webob@1.8.7
1.8.8
1
galaxy/galaxy-init:v18.010267bad550e6
webob@1.4.1
1.8.8
1
mozilla/syncserver:latest016162bf39d8
webob@1.8.5
1.8.8
1
mozilla/syncstorage-rs:0.15.893752877dced
webob@1.8.7
1.8.8
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
webob@1.8.2
1.8.8
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
webob@1.8.2
1.8.8
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
webob@1.8.7
1.8.8
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
webob@1.8.7
1.8.8
1
stackstorm/st2actionrunner:3.888235ba70cad
webob@1.8.7
1.8.8
1
stackstorm/st2api:3.86f56d239d280
webob@1.8.7
1.8.8
1
stackstorm/st2auth:3.833ecfda16608
webob@1.8.7
1.8.8
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
webob@1.8.7
1.8.8
1
stackstorm/st2notifier:3.8f190a6212195
webob@1.8.7
1.8.8
1
stackstorm/st2rulesengine:3.8259503496ff9
webob@1.8.7
1.8.8
1
stackstorm/st2scheduler:3.8b1de2055c362
webob@1.8.7
1.8.8
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
webob@1.8.7
1.8.8
1
stackstorm/st2stream:3.81c8904a3bf67
webob@1.8.7
1.8.8
1
stackstorm/st2timersengine:3.81bf35bfaf00c
webob@1.8.7
1.8.8
1
stackstorm/st2workflowengine:3.819fdfffdbba8
webob@1.8.7
1.8.8
1
statcan/ckan:2.93921305425b8
webob@1.8.5
1.8.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.