CVE-2024-4741
HighAdvisory
Published 28 May 2024In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.029
- 86th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,517
- of 17,792 indexed, latest versions
- Container images
- 1,593
- deployed by those charts
- Fix available
- 3 of 4
- affected packages
Security update for openssl-1_1
Carried by container images the latest versions of 1,517 of 17,792 indexed charts deploy, on 1,593 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+79 more | 1.1.1f-1ubuntu2.23, 3.0.2-0ubuntu1.17, 3.0.13-0ubuntu3.2, 3.0.14-1~deb12u1 | 953 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+24 more | 3.0.14-r0, 3.1.6-r0, 3.3.0-r3, 3.3.1-r0 | 639 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 more | no fix listed | 16 |
| openssl-1_1rpm | 1.1.1d-11.6.1 | 1.1.1d-150200.11.91.1 | 1 |
- OSV records
- ALPINE-CVE-2024-4741CGA-53qp-wmg8-pjf3DEBIAN-CVE-2024-4741UBUNTU-CVE-2024-4741SUSE-SU-2024:2035-1
- Also known as
- CGA-47j4-6g2h-8vfm, CGA-mq9p-h95f-gfhr, CGA-v662-x97w-gx7w, USN-6937-1
Charts affected
1,517 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| oauth2xdVerified publisher | 1.0.0 | 1 of 1See more | 2,008 |
| owlxdVerified publisher | 0.5.1 | 2 of 2See more | 3,882 |
| passportxdVerified publisher | 0.2.16 | 2 of 2See more | 3,976 |
| tabbyxdVerified publisher | 1.0.6 | 2 of 2See more | 7,697 |
| treexdVerified publisher | 0.1.10 | 1 of 1See more | 1,998 |
| zooxdVerified publisher | 0.4.0 | 1 of 1See more | 1,955 |
| xlinexline | 0.0.1 | 1 of 1See more | 2,142 |
| prometheusalertygqygq2Verified publisher | 1.0.0 | 1 of 1See more | 1,610 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,684 |
| zahori-consulzahoriVerified publisher | 1.0.1 | 2 of 2See more | 5,047 |
| zahori-postgresqlzahoriVerified publisher | 1.0.1 | 1 of 1See more | 448 |
| zahori-processzahoriVerified publisher | 1.0.1 | 1 of 1See more | 3,487 |
| zahori-schedulerzahoriVerified publisher | 1.0.1 | 1 of 1See more | 2,467 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 2 of 2See more | 5,852 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,588 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,256 |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 7,929 |
Container images carrying it
1,593 by charts deploying them
A fixed version is listed for 3 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| thirtythreeforty/ | f564c4f538de | openssl | 3.0.14-r0 | 1 |
| thmmniii/ | 5438517d9fc2 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| thmmniii/ | 86105349c1a3 | openssl | 3.1.6-r0 | 1 |
| thongngo3301/ | a341af5976e3 | openssl | 3.0.14-1~deb12u1 | 1 |
| timescale/ | 645fd9e92d76 | openssl | 3.1.6-r0 | 1 |
| timescale/ | a8e3322e1cf9 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| timescale/ | cdb9ae118899 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| timescale/ | d7db8f1085a3 | openssl | no fix listed | 1 |
| timescale/ | e8d0a9cc3db5 | openssl | no fix listed | 1 |
| timescale/ | ed719c0cd19d | openssl | 3.0.2-0ubuntu1.17 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | nodejs openssl | no fix listed no fix listed | 1 |
| tiredofit/ | 5b7cc0658f07 | openssl | 3.1.6-r0 | 1 |
| tobirachel/ | 7d9f37154994 | openssl | 3.0.14-r0 | 1 |
| tomsajan/ | fb61907707b8 | openssl | 3.1.6-r0 | 1 |
| tpdock/ | 3da600c95a49 | openssl | no fix listed | 1 |
| tranhailong/ | 028662749be2 | openssl | 3.0.14-r0 | 1 |
| trinodb/ | ee80ab5eeab2 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| trueosiris/ | 9356f98ad561 | openssl | no fix listed | 1 |
| tundeficky/ | 3cf9a9ce54e8 | openssl | 3.0.14-r0 | 1 |
| tusproject/ | f8088058b80f | openssl | 3.1.6-r0 | 1 |
| twentycrm/ | 2f78405a78be | openssl | 3.0.2-0ubuntu1.17 | 1 |
| typesense/ | 035ccfbc3fd8 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| typesense/ | 3accb727cbe2 | openssl | no fix listed | 1 |
| typesense/ | 91604dc128e2 | openssl | no fix listed | 1 |
| typesense/ | dea1b62b7b6e | openssl | no fix listed | 1 |
| ubuntu/ | 5ee73f44e5d0 | openssl | no fix listed | 1 |
| ubuntu/ | 723891b5bc74 | openssl | no fix listed | 1 |
| udhos/ | 12e120d39fdb | openssl | 3.1.6-r0 | 1 |
| udhos/ | e432012dd34a | openssl | 3.0.14-r0 | 1 |
| untergeek/ | de5197f06c3c | openssl | 3.0.14-r0 | 1 |
| vaultwarden/ | 7cd450642c54 | openssl | 3.0.14-r0 | 1 |
| vectorim/ | f8aafe0fe70b | openssl | 3.1.6-r0 | 1 |
| velero/ | e4d1e79be2ee | openssl | no fix listed | 1 |
| vexorian/ | 7e2b99844a5c | openssl | no fix listed | 1 |
| victoriametrics/ | 77a9815d0640 | openssl | 3.1.6-r0 | 1 |
| victoriametrics/ | f52723a08a44 | openssl | 3.1.6-r0 | 1 |
| victoriametrics/ | 150cd08fde94 | openssl | 3.1.6-r0 | 1 |
| vientoprojects/ | eb2a71531741 | openssl | no fix listed | 1 |
| vinanrra/ | f9534490bd2b | nodejs openssl | no fix listed no fix listed | 1 |
| vineyardcloudnative/ | 9d419aa18faa | openssl | 3.0.14-1~deb12u1 | 1 |
| visualregressiontracker/ | f983a1d4306e | openssl | 3.1.6-r0 | 1 |
| visualregressiontracker/ | ca7835844257 | openssl | 3.0.14-r0 | 1 |
| vlebediantsev/ | 007c6670ff48 | openssl | 3.0.14-1~deb12u1 | 1 |
| vlebediantsev/ | 945675fd2636 | openssl | 3.0.14-1~deb12u1 | 1 |
| vlebediantsev/ | 54f69d116c50 | openssl | 3.0.14-1~deb12u1 | 1 |
| volkerraschek/ | e4cf12c6249d | openssl | 3.0.14-r0 | 1 |
| voltha/ | c4e41e92f046 | openssl | no fix listed | 1 |
| voltha/ | 59ab2a00f712 | openssl | no fix listed | 1 |
| voltha/ | 37f80524c207 | openssl | no fix listed | 1 |
| voltha/ | 9ee8c1f4428c | openssl | no fix listed | 1 |