StackRadar

CVE-2024-53899

Critical

Advisory

Published 24 Nov 2024In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
73
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: python36:3.6 security update

Carried by container images the latest versions of 73 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
virtualenvpypi1.11.4, 15.1.0, 16.3.0, 16.6.0+32 more20.26.672
python-virtualenvdeb1.11.4-1ubuntu1, 20.0.17-1ubuntu0.3, 20.17.1+ds-1, 20.25.0+ds-220.0.17-1ubuntu0.4+esm1, 20.25.0+ds-2ubuntu0.1~esm19
python36rpm3.6.8-2.module+el8.1.0+3334+5cb623d7, 3.6.8-2.module+el8.4.0+15040+36b018e7.1, 3.6.8-38.module+el8.5.0+12207+5c5719bc, 3.6.8-38.module+el8.9.0+20976+d3c385250:3.6.8-39.module+el8.10.0+20784+edafcd4319
python-wheelrpm1:0.31.1-2.module+el8.1.0+3724+3c0970901:0.31.1-3.module+el8.10.0+20784+edafcd431
OSV records
PYSEC-2024-187DEBIAN-CVE-2024-53899RHSA-2024:10953UBUNTU-CVE-2024-53899USN-7271-1
Also known as
BIT-virtualenv-2024-53899, GHSA-rqc4-2hc7-8c8v, RHSA-2025:0002, USN-7271-2

Charts affected

73 by stars
ChartLatestAffected imagesRadar Score
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
virtualenv@20.17.1
20.26.6

Open the chart page →

3,891
lnbitslnbits0.2.11 of 1See more

lnbits lnbits 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
virtualenv@20.21.1
20.26.6

Open the chart page →

1,949
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
virtualenv@20.20.0
20.26.6

Open the chart page →

5,456
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
python36@3.6.8-38.module+el8.9.0+20976+d3c38525
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,796
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

9,968
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
virtualenv@16.7.6
20.26.6

Open the chart page →

36,215
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1

Open the chart page →

71,208
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,466
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,151
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
virtualenv@20.24.5
20.26.6

Open the chart page →

12,754
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
virtualenv@20.26.4
20.26.6

Open the chart page →

21,211
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

16,047
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
virtualenv@20.26.3
20.26.6

Open the chart page →

5,790
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
virtualenv@20.24.3
20.26.6

Open the chart page →

4,908
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
virtualenv@20.25.0
20.26.6

Open the chart page →

10,209
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
virtualenv@20.21.1
20.26.6

Open the chart page →

5,565
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
virtualenv@20.19.0
20.26.6

Open the chart page →

1,009
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

28,165
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
virtualenv@15.1.0
20.26.6

Open the chart page →

3,116

Container images carrying it

91 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
localstack/localstack:3.19d278167f2b7
virtualenv@20.25.0
20.26.6
1
milesmcc/shynet:v0.13.1ba54f7797a6b
virtualenv@20.21.1
20.26.6
1
milesmcc/shynet:v0.12.0e821e31140f7
virtualenv@20.12.0
20.26.6
1
mshanley80/httpbin2022:latest5b189a70c0fb
virtualenv@20.17.1
20.26.6
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
virtualenv@20.7.2
20.26.6
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
virtualenv@20.7.2
20.26.6
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
virtualenv@16.7.6
20.26.6
1
pangeo/base-notebook:2024.01.155fbe688a4f80
virtualenv@20.25.0
20.26.6
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
virtualenv@20.24.5
20.26.6
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
virtualenv@20.24.3
20.26.6
1
redislabs/redisearch:2.4.1433561794c5c8
virtualenv@20.16.3
20.26.6
1
runx1/opta-agent:latest0ca3867d3200
virtualenv@20.14.1
20.26.6
1
stackstorm/st2actionrunner:3.888235ba70cad
virtualenv@20.4.0
20.26.6
1
stackstorm/st2api:3.86f56d239d280
virtualenv@20.4.0
20.26.6
1
stackstorm/st2auth:3.833ecfda16608
virtualenv@20.4.0
20.26.6
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
virtualenv@20.4.0
20.26.6
1
stackstorm/st2notifier:3.8f190a6212195
virtualenv@20.4.0
20.26.6
1
stackstorm/st2rulesengine:3.8259503496ff9
virtualenv@20.4.0
20.26.6
1
stackstorm/st2scheduler:3.8b1de2055c362
virtualenv@20.4.0
20.26.6
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
virtualenv@20.4.0
20.26.6
1
stackstorm/st2stream:3.81c8904a3bf67
virtualenv@20.4.0
20.26.6
1
stackstorm/st2timersengine:3.81bf35bfaf00c
virtualenv@20.4.0
20.26.6
1
stackstorm/st2workflowengine:3.819fdfffdbba8
virtualenv@20.4.0
20.26.6
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
virtualenv@15.1.0
20.26.6
1
statcan/ckan:2.93921305425b8
virtualenv@20.0.17
python-virtualenv@20.0.17-1ubuntu0.3
20.26.6
20.0.17-1ubuntu0.4+esm1
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
virtualenv@20.14.1
20.26.6
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
virtualenv@20.24.7
20.26.6
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
virtualenv@20.21.1
20.26.6
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
virtualenv@20.26.1
20.26.6
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
virtualenv@20.25.0
20.26.6
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
quay.io/openshift/origin-cli:4.66722d5041b47
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.