StackRadar

CVE-2024-47220

High

Advisory

Published 22 Sept 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
58
of 17,781 indexed, latest versions
Container images
65
deployed by those charts
Fix available
4 of 4
affected packages

HTTP Request Smuggling in ruby webrick

Carried by container images the latest versions of 58 of 17,781 indexed charts deploy, on 65 images.

Affected packageAffected versionsFixed inImages
webrickgem1.4.2, 1.4.4, 1.6.0, 1.6.1+2 more1.8.263
ruby2.7deb2.7.0-5ubuntu1.4, 2.7.0-5ubuntu1.5, 2.7.0-5ubuntu1.82.7.0-5ubuntu1.18+esm36
ruby2.3deb2.3.1-2~16.04.52.3.1-2~ubuntu16.04.16+esm112
ruby-webrickdeb1.7.0-31.7.0-3ubuntu0.11
OSV records
GHSA-6f62-3596-g6w7UBUNTU-CVE-2024-47220
Also known as
USN-7057-2, USN-7840-1

Charts affected

58 by stars
ChartLatestAffected imagesRadar Score
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
webrick@1.4.2
1.8.2

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
webrick@1.4.2
1.8.2

Open the chart page →

20,462
coralogix-fluentdromholdings1.0.31 of 1See more

coralogix-fluentd romholdings 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.8.2

Open the chart page →

750
fluentdslamdev0.0.61 of 1See more

fluentd slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
webrick@1.4.2
1.8.2

Open the chart page →

1,384
fluentd-operatorstatcan0.5.11 of 1See more

fluentd-operator statcan 0.5.1

1 of the 1 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
vmware/kube-fluentd-operator:latestf028c138a5f4
webrick@1.8.1
1.8.2

Open the chart page →

1,955
velero-notificationsvelero-notifications1.1.01 of 1See more

velero-notifications velero-notifications 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
webrick@1.6.1
1.8.2

Open the chart page →

1,285
kongwallarmVerified publisher4.6.32 of 7See more

kong wallarm 4.6.3

2 of the 7 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
webrick@1.6.1
1.8.2
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
webrick@1.6.0
ruby2.7@2.7.0-5ubuntu1.8
1.8.2
2.7.0-5ubuntu1.18+esm3

Open the chart page →

11,405
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2024-47220.

Container imageDigestPackageFixed in
wallarm/ingress-ruby:4.2.1-195ea2632326c
webrick@1.6.1
1.8.2

Open the chart page →

2,905

Container images carrying it

65 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.8.2
4
chatwoot/chatwoot:v3.1.0d530ab8c1753
webrick@1.8.1
1.8.2
2
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
webrick@1.4.2
1.8.2
2
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
webrick@1.4.2
1.8.2
2
pecan/bety:5.4.1f825d480cd62
webrick@1.4.4
1.8.2
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
webrick@1.7.0
1.8.2
2
bryanalves/fluentd:0.5d3605be4b178
webrick@1.4.2
1.8.2
1
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
webrick@1.4.2
1.8.2
1
bryanalves/smart_exporter:0.2af47dfbb9413
webrick@1.4.2
1.8.2
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
webrick@1.4.2
1.8.2
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
webrick@1.4.2
1.8.2
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
webrick@1.4.2
1.8.2
1
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
webrick@1.4.2
1.8.2
1
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
webrick@1.4.2
1.8.2
1
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
webrick@1.4.2
1.8.2
1
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
webrick@1.4.2
1.8.2
1
fluent/fluentd-kubernetes-daemonset:v1.14.0-debian-elasticsearch7-1.03933cae61054
webrick@1.4.4
1.8.2
1
fluent/fluentd-kubernetes-daemonset:v1.12.4-debian-elasticsearch7-1.0656423b5fabb
webrick@1.7.0
1.8.2
1
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
webrick@1.4.2
1.8.2
1
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
webrick@1.4.2
1.8.2
1
gollumorg/gollum:latest7cd5305a3cf7
webrick@1.6.0
1.8.2
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
webrick@1.4.2
1.8.2
1
istio/examples-bookinfo-details-v1:1.17.02b081e3c86dd
webrick@1.6.0
1.8.2
1
jordan/icinga2:latestf75025fe8ea8
webrick@1.8.1
1.8.2
1
klausmeyer/docker-registry-browser:1.3.5430a440d95af
webrick@1.6.0
1.8.2
1
kubesphere/examples-bookinfo-details-v1:1.13.0108d022f64f0
webrick@1.4.2
1.8.2
1
library/logstash:7.17.817a4f64e9cf5
webrick@1.6.1
1.8.2
1
logicmonitor/lm-logs-k8s-fluentd:1.0.55ac21b3f1572
webrick@1.8.1
1.8.2
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
webrick@1.4.2
1.8.2
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
webrick@1.4.2
1.8.2
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
webrick@1.4.2
1.8.2
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
webrick@1.4.2
1.8.2
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
webrick@1.4.2
1.8.2
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
webrick@1.4.2
1.8.2
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
2.3.1-2~ubuntu16.04.16+esm11
1
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
2.3.1-2~ubuntu16.04.16+esm11
1
openproject/community:12.0.2734743d11094
webrick@1.6.1
1.8.2
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
webrick@1.7.0
1.8.2
1
pactfoundation/pact-broker:2.32.0-2062d6c710099
webrick@1.4.2
1.8.2
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
webrick@1.7.0
1.8.2
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
webrick@1.7.0
1.8.2
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
webrick@1.6.1
1.8.2
1
uffizzi/app:latest66e9e3937c60
webrick@1.6.1
1.8.2
1
vmware/kube-fluentd-operator:latestf028c138a5f4
webrick@1.8.1
1.8.2
1
wallarm/ingress-ruby:4.2.1-195ea2632326c
webrick@1.6.1
1.8.2
1
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
webrick@1.6.1
1.8.2
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
webrick@1.6.0
ruby2.7@2.7.0-5ubuntu1.8
1.8.2
2.7.0-5ubuntu1.18+esm3
1
zammad/zammad-docker-compose:zammad-4.1.0-312808e2dfa810
webrick@1.4.2
1.8.2
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
webrick@1.4.2
1.8.2
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
webrick@1.4.2
1.8.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.