CVE-2024-5535
CriticalAdvisory
Published 27 Jun 2024In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.056
- 92nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,711
- of 17,787 indexed, latest versions
- Container images
- 1,868
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Red Hat Security Advisory: openssl security update
Carried by container images the latest versions of 1,711 of 17,787 indexed charts deploy, on 1,868 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+80 more | 1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.23+4 more | 1,036 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+25 more | 3.0.14-r0, 3.1.6-r0, 3.3.1-r1, 3.3.1-r3 | 648 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 more | no fix listed | 16 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm6 | 15 |
| opensslrpm | 1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+15 more | 1:1.1.1k-14.el8_6, 1:1.1.1k-14.el8_10, 1:3.0.7-29.el9_4 | 183 |
| openssl-1_1rpm | 1.1.1d-11.6.1 | 1.1.1d-150200.11.94.1 | 1 |
- OSV records
- ALPINE-CVE-2024-5535CGA-6r9r-wppq-f3vfDEBIAN-CVE-2024-5535UBUNTU-CVE-2024-5535RHSA-2024:7846RHSA-2024:7847RHSA-2024:7848RHSA-2025:3666RLSA-2024:7848SUSE-SU-2024:2909-1
- Also known as
- CGA-r27g-x88q-7j3g, USN-6937-1, USN-8678-2
Charts affected
1,711 by stars
Container images carrying it
1,868 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| grafana/ | 0dc5a246ab16 | openssl | 3.1.6-r0 | 3 |
| jacobalberty/ | 896c0ab82d33 | openssl | 1.1.1f-1ubuntu2.24+esm5 | 3 |
| library/ | af96c680a7e1 | openssl | 3.1.6-r0 | 3 |
| library/ | 516475cc129d | openssl | 3.1.6-r0 | 3 |
| library/ | a484819eb602 | openssl | 3.0.15-1~deb12u1 | 3 |
| library/ | c8bb255c3559 | openssl | 3.1.6-r0 | 3 |
| minio/ | bd11edda91f3 | openssl | 1:1.1.1k-14.el8_6 | 3 |
| natsio/ | b3359eeb10bf | openssl | 3.1.6-r0 | 3 |
| nginxinc/ | be76a26e238d | openssl | 3.1.6-r0 | 3 |
| omecproject/ | d59ccb138ffb | openssl | 1.0.2g-1ubuntu4.20+esm18 | 3 |
| oryd/ | 2c93beb5e5f2 | openssl | 3.1.6-r0 | 3 |
| pnnlmiscscripts/ | 9a2fe06a1472 | openssl | 3.0.14-r0 | 3 |
| rcdelacruz/ | 38007f358355 | openssl | 3.1.6-r0 | 3 |
| rss3/ | d1d2ae6efd05 | openssl | 3.1.6-r0 | 3 |
| selenium/ | 02f251d48d5f | openssl | 1.1.1f-1ubuntu2.23 | 3 |
| sigp/ | 50f66cfebb6d | openssl | no fix listed | 3 |
| xenondb/ | 0e26872a2b67 | openssl | 1.1.1f-1ubuntu2.23 | 3 |
| ghcr.io/ | 6a5594b7b32c | openssl | 3.0.15-1~deb12u1 | 3 |
| ghcr.io/ | 0502794a4d86 | openssl | 3.0.15-1~deb12u1 | 3 |
| quay.io/ | 6545dac92173 | openssl | 3.0.15-1~deb12u1 | 3 |
| quay.io/ | 2b6db27eaf3d | openssl | 3.0.2-0ubuntu1.17 | 3 |
| quay.io/ | bc4aa22272ef | openssl | 1:1.1.1k-14.el8_6 | 3 |
| quay.io/ | 75fb847ac045 | openssl | 1:1.1.1k-14.el8_6 | 3 |
| quay.io/ | f6269309455a | openssl | 3.1.6-r0 | 3 |
| quay.io/ | 39f2c6e0af38 | openssl | 1.1.1f-1ubuntu2.23 | 3 |
| quay.io/ | 4c3b91bebd3d | openssl | 1.0.2g-1ubuntu4.20+esm18 | 3 |
| quay.io/ | 4286bcccda3e | openssl | 3.1.6-r0 | 3 |
| quay.io/ | f296c2ec5db7 | openssl | 3.0.2-0ubuntu1.17 | 3 |
| quay.io/ | eec0305b594c | openssl | 3.1.6-r0 | 3 |
| quay.io/ | fd916f75415f | openssl | 3.1.6-r0 | 3 |
| quay.io/ | 1b33357b3595 | openssl | 3.1.6-r0 | 3 |
| quay.io/ | a7dff785d821 | openssl | 1:1.1.1k-14.el8_6 | 3 |
| quay.io/ | c68135620167 | openssl | 1:1.1.1k-14.el8_6 | 3 |
| registry.k8s.io/ | e5c4824e7375 | openssl | 3.1.6-r0 | 3 |
| agoldis/ | afaa5a84051d | openssl | 3.1.6-r0 | 2 |
| agoldis/ | e061e5714238 | openssl | 3.0.14-r0 | 2 |
| agoldis/ | 10228ecd353b | openssl | 3.1.6-r0 | 2 |
| alpine/ | f0c1b7ca12f6 | openssl | 3.3.1-r1 | 2 |
| apache/ | 7cdfd8deec92 | openssl | 3.0.2-0ubuntu1.17 | 2 |
| apache/ | afe59523a6c8 | openssl | 3.1.6-r0 | 2 |
| apache/ | ae0b86d3c4d0 | openssl | 3.0.13-0ubuntu3.2 | 2 |
| bitnamilegacy/ | 94bc968141e7 | openssl | 3.0.15-1~deb12u1 | 2 |
| cfssl/ | c9018c2ddf0b | openssl | 3.0.15-1~deb12u1 | 2 |
| chatwoot/ | d530ab8c1753 | openssl | 3.1.6-r0 | 2 |
| clickhouse/ | ed9640bfff07 | openssl | 1.1.1f-1ubuntu2.23 | 2 |
| clickhouse/ | f226fe41f057 | openssl | 3.1.6-r0 | 2 |
| clickhouse/ | fa394da808cc | openssl | no fix listed | 2 |
| confluentinc/ | ac776fad95a5 | openssl | 1:1.1.1k-14.el8_6 | 2 |
| confluentinc/ | cae577096489 | openssl | 1:1.1.1k-14.el8_6 | 2 |
| cs3org/ | 02a9e78757b4 | openssl | 3.0.14-r0 | 2 |