StackRadar

CVE-2024-53899

Critical

Advisory

Published 24 Nov 2024In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
73
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: python36:3.6 security update

Carried by container images the latest versions of 73 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
virtualenvpypi1.11.4, 15.1.0, 16.3.0, 16.6.0+32 more20.26.672
python-virtualenvdeb1.11.4-1ubuntu1, 20.0.17-1ubuntu0.3, 20.17.1+ds-1, 20.25.0+ds-220.0.17-1ubuntu0.4+esm1, 20.25.0+ds-2ubuntu0.1~esm19
python36rpm3.6.8-2.module+el8.1.0+3334+5cb623d7, 3.6.8-2.module+el8.4.0+15040+36b018e7.1, 3.6.8-38.module+el8.5.0+12207+5c5719bc, 3.6.8-38.module+el8.9.0+20976+d3c385250:3.6.8-39.module+el8.10.0+20784+edafcd4319
python-wheelrpm1:0.31.1-2.module+el8.1.0+3724+3c0970901:0.31.1-3.module+el8.10.0+20784+edafcd431
OSV records
PYSEC-2024-187DEBIAN-CVE-2024-53899RHSA-2024:10953UBUNTU-CVE-2024-53899USN-7271-1
Also known as
BIT-virtualenv-2024-53899, GHSA-rqc4-2hc7-8c8v, RHSA-2025:0002, USN-7271-2

Charts affected

73 by stars
ChartLatestAffected imagesRadar Score
large-systems-djangolarge-systems-djangoVerified publisher1.0.01 of 1See more

large-systems-django large-systems-django 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
ha33ona/python:test6affdfc644d0
virtualenv@20.17.1
20.26.6

Open the chart page →

3,891
lnbitslnbits0.2.11 of 1See more

lnbits lnbits 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
virtualenv@20.21.1
20.26.6

Open the chart page →

1,949
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
virtualenv@20.20.0
20.26.6

Open the chart page →

5,456
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
python36@3.6.8-38.module+el8.9.0+20976+d3c38525
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,796
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

9,968
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
virtualenv@16.7.6
20.26.6

Open the chart page →

36,215
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.05 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

5 of the 40 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
virtualenv@20.25.0+ds
python-virtualenv@20.25.0+ds-2
20.26.6
20.25.0+ds-2ubuntu0.1~esm1

Open the chart page →

71,208
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,466
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,151
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
virtualenv@20.24.5
20.26.6

Open the chart page →

12,754
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
virtualenv@20.26.4
20.26.6

Open the chart page →

21,211
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

16,047
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
virtualenv@20.26.3
20.26.6

Open the chart page →

5,790
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
virtualenv@20.24.3
20.26.6

Open the chart page →

4,908
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
virtualenv@20.25.0
20.26.6

Open the chart page →

10,209
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
virtualenv@20.21.1
20.26.6

Open the chart page →

5,565
downscalersqream-chartsVerified publisher1.0.01 of 1See more

downscaler sqream-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.05d328c003efe
virtualenv@20.19.0
20.26.6

Open the chart page →

1,009
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43

Open the chart page →

28,165
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-53899.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
virtualenv@15.1.0
20.26.6

Open the chart page →

3,116

Container images carrying it

91 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43
3
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
virtualenv@20.23.1
20.26.6
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
python36@3.6.8-2.module+el8.4.0+15040+36b018e7.1
0:3.6.8-39.module+el8.10.0+20784+edafcd43
2
akeyless/base-rhel:0.0.14ba8900a0061
python36@3.6.8-38.module+el8.9.0+20976+d3c38525
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
alerta/alerta-web:8.5.04786b9eaa606
virtualenv@20.10.0
20.26.6
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
virtualenv@20.15.0
20.26.6
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
python-wheel@1:0.31.1-2.module+el8.1.0+3724+3c097090
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
1:0.31.1-3.module+el8.10.0+20784+edafcd43
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
apache/airflow:2.8.4-python3.964e58748b6b9
virtualenv@20.25.1
20.26.6
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
virtualenv@20.26.4
20.26.6
1
apache/airflow:2.8.1e5560ad0b86e
virtualenv@20.25.0
20.26.6
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
virtualenv@20.26.3
20.26.6
1
camerahub/camerahub:0.36.23a5af37dd6e1b
virtualenv@20.21.1
20.26.6
1
cdignam/kodiak:v0.54.05a6a55b39cee
virtualenv@20.15.1
20.26.6
1
codecov/self-hosted-api:24.4.10475cb1c3136
virtualenv@20.4.3
20.26.6
1
codecov/self-hosted-worker:24.4.1837f546b479b
virtualenv@20.24.5
20.26.6
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
python36@3.6.8-38.module+el8.5.0+12207+5c5719bc
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
python36@3.6.8-2.module+el8.1.0+3334+5cb623d7
0:3.6.8-39.module+el8.10.0+20784+edafcd43
1
djjudas21/autonodelabel:0.0.6f17233350c4f
virtualenv@20.24.2
20.26.6
1
evk02/mlflow:2.2.1ef6ff257ef35
virtualenv@20.20.0
20.26.6
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
virtualenv@20.17.1
20.26.6
1
galaxy/galaxy-init:v18.010267bad550e6
virtualenv@1.11.4
python-virtualenv@1.11.4-1ubuntu1
20.26.6
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
virtualenv@1.11.4
python-virtualenv@1.11.4-1ubuntu1
20.26.6
no fix listed
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
virtualenv@20.17.1+ds
python-virtualenv@20.17.1+ds-1
20.26.6
no fix listed
1
gethue/hue:4.11.011b649636e68
virtualenv@20.16.5
20.26.6
1
gethue/hue:4.10.05702b2c37ff9
virtualenv@20.4.7
20.26.6
1
gethue/hue:latest7d5c1b9f8a79
virtualenv@20.24.4
20.26.6
1
ha33ona/python:test6affdfc644d0
virtualenv@20.17.1
20.26.6
1
hayk96/alerta-web:9.0.486377705e9e3
virtualenv@20.26.3
20.26.6
1
hhyo/archery:v1.9.11aa41843419e
virtualenv@20.15.1
20.26.6
1
hjacobs/kube-downscaler:23.2.05d328c003efe
virtualenv@20.19.0
20.26.6
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
virtualenv@20.23.1
20.26.6
1
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
virtualenv@20.21.1
20.26.6
1
hjacobs/kube-resource-report:22.11.0c173cd02f5af
virtualenv@20.17.0
20.26.6
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
virtualenv@20.24.3
20.26.6
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
virtualenv@20.14.1
20.26.6
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
virtualenv@20.24.5
20.26.6
1
homeassistant/home-assistant:2023.12.48d000332b09b
virtualenv@20.25.0
20.26.6
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
virtualenv@16.6.0
20.26.6
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
virtualenv@16.3.0
20.26.6
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
virtualenv@16.7.9
20.26.6
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
virtualenv@16.7.9
20.26.6
1
lnbitsdocker/lnbits-legend:latest26fae6327477
virtualenv@20.25.0
20.26.6
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
virtualenv@20.21.1
20.26.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.