StackRadar

CVE-2024-44905

Medium

Advisory

Published 12 Jun 2025In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 2
affected packages

go-pg SQL injection vulnerability via the component /types/append_value.go

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
github.com/go-pg/pggolangv6.15.1+incompatible, v8.0.7+incompatibleno fix listed14
github.com/go-pg/pg/v10golangv10.11.0, v10.11.1, v10.14.010.15.05
OSV records
GHSA-6xp3-p59p-q4fj
Also known as
GO-2025-3764

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
devtron-operatordevtron0.23.34 of 11See more

devtron-operator devtron 0.23.3

4 of the 11 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

32,902
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
github.com/go-pg/pg/v10@v10.11.1
10.15.0
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
github.com/go-pg/pg/v10@v10.11.1
10.15.0

Open the chart page →

32,501
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
github.com/go-pg/pg@v6.15.1+incompatible
github.com/go-pg/pg/v10@v10.14.0
no fix listed
10.15.0

Open the chart page →

68,240
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

5,039
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

2,435
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
github.com/go-pg/pg@v6.15.1+incompatible
github.com/go-pg/pg/v10@v10.14.0
no fix listed
10.15.0

Open the chart page →

68,240
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

5,039
devtron-operatordevtron-labs0.23.34 of 11See more

devtron-operator devtron-labs 0.23.3

4 of the 11 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

32,902
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

2,435
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
github.com/go-pg/pg/v10@v10.11.0
10.15.0

Open the chart page →

1,940
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
github.com/go-pg/pg/v10@v10.11.0
10.15.0

Open the chart page →

1,940
devtron-enterpriseromholdings48.0.09 of 28See more

devtron-enterprise romholdings 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
github.com/go-pg/pg@v6.15.1+incompatible
github.com/go-pg/pg/v10@v10.14.0
no fix listed
10.15.0

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

5,039
devtron-operatorromholdings0.23.34 of 11See more

devtron-operator romholdings 0.23.3

4 of the 11 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

32,902
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-44905.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed

Open the chart page →

2,435

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
github.com/go-pg/pg@v8.0.7+incompatible
no fix listed
6
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/cost-sync:172ef62b-1159-39429edf210d763ca
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/go-pg/pg@v6.15.1+incompatible
no fix listed
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
github.com/go-pg/pg@v6.15.1+incompatible
github.com/go-pg/pg/v10@v10.14.0
no fix listed
10.15.0
3
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
github.com/go-pg/pg/v10@v10.11.0
10.15.0
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
github.com/go-pg/pg/v10@v10.11.0
10.15.0
1
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
github.com/go-pg/pg/v10@v10.11.1
10.15.0
1
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
github.com/go-pg/pg/v10@v10.11.1
10.15.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.