StackRadar

CVE-2024-53263

High

Advisory

Published 14 Jan 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: git-lfs security update

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
git-lfsdeb2.13.2-1+b5, 3.0.2-1, 3.0.2-1ubuntu0.2, 3.4.1-1ubuntu0.2+1 more2.13.2-1+deb11u1, 3.0.2-1ubuntu0.3+esm2, 3.4.1-1ubuntu0.3+esm27
git-lfsrpm2.13.3-3.el8_60:2.13.3-3.el8_6.31
OSV records
RHSA-2025:0765UBUNTU-CVE-2024-53263DLA-4028-1
Also known as
RHSA-2025:0845, USN-7977-1

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
git-lfs@3.4.1-1ubuntu0.3
3.4.1-1ubuntu0.3+esm2

Open the chart page →

5,240
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
git-lfs@3.0.2-1ubuntu0.2
3.0.2-1ubuntu0.3+esm2

Open the chart page →

10,315
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

10,037
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
git-lfs@2.13.2-1+b5
2.13.2-1+deb11u1

Open the chart page →

31,844
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

7,300
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
git-lfs@3.0.2-1
3.0.2-1ubuntu0.3+esm2

Open the chart page →

13,450
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

6,037
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2

Open the chart page →

25,934
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-53263.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
git-lfs@2.13.3-3.el8_6
0:2.13.3-3.el8_6.3

Open the chart page →

16,047

Container images carrying it

8 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/argoproj/argocd:v2.14.115fc69e31c755
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2
2
1dev/server:11.9.0cd5b12fe5471
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2
1
codercom/code-server:4.11.0-debian1e2cc688008e
git-lfs@2.13.2-1+b5
2.13.2-1+deb11u1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
git-lfs@3.0.2-1
3.0.2-1ubuntu0.3+esm2
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
git-lfs@3.4.1-1ubuntu0.2
3.4.1-1ubuntu0.3+esm2
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
git-lfs@3.4.1-1ubuntu0.3
3.4.1-1ubuntu0.3+esm2
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
git-lfs@3.0.2-1ubuntu0.2
3.0.2-1ubuntu0.3+esm2
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
git-lfs@2.13.3-3.el8_6
0:2.13.3-3.el8_6.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.