CVE-2024-5535
CriticalAdvisory
Published 27 Jun 2024In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.056
- 92nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,716
- of 17,790 indexed, latest versions
- Container images
- 1,876
- deployed by those charts
- Fix available
- 5 of 6
- affected packages
Red Hat Security Advisory: openssl security update
Carried by container images the latest versions of 1,716 of 17,790 indexed charts deploy, on 1,876 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+80 more | 1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.23+4 more | 1,039 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+25 more | 3.0.14-r0, 3.1.6-r0, 3.3.1-r1, 3.3.1-r3 | 653 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 more | no fix listed | 16 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm6 | 15 |
| opensslrpm | 1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+15 more | 1:1.1.1k-14.el8_6, 1:1.1.1k-14.el8_10, 1:3.0.7-29.el9_4 | 183 |
| openssl-1_1rpm | 1.1.1d-11.6.1 | 1.1.1d-150200.11.94.1 | 1 |
- OSV records
- ALPINE-CVE-2024-5535CGA-6r9r-wppq-f3vfDEBIAN-CVE-2024-5535UBUNTU-CVE-2024-5535RHSA-2024:7846RHSA-2024:7847RHSA-2024:7848RHSA-2025:3666RLSA-2024:7848SUSE-SU-2024:2909-1
- Also known as
- CGA-r27g-x88q-7j3g, USN-6937-1, USN-8678-2
Charts affected
1,716 by stars
Container images carrying it
1,876 by charts deploying them
A fixed version is listed for 5 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 0708d30433d4 | openssl | 3.3.1-r1 | 1 |
| ghcr.io/ | 344f53763b25 | openssl | 3.0.15-1~deb12u1 | 1 |
| ghcr.io/ | d81cda253f5c | openssl | 3.3.1-r1 | 1 |
| ghcr.io/ | da0b5eb7721a | openssl | no fix listed | 1 |
| mcr.microsoft.com/ | bccaa701e2df | openssl | 1.1.1f-1ubuntu2.23 | 1 |
| mcr.microsoft.com/ | 13221ac5f673 | openssl openssl1.0 | 1.1.1-1ubuntu2.1~18.04.23+esm10 1.0.2n-1ubuntu5.13+esm6 | 1 |
| mcr.microsoft.com/ | 49a57dc220b1 | openssl | 1.1.1f-1ubuntu2.23 | 1 |
| mcr.microsoft.com/ | ba4c8329f48f | openssl | no fix listed | 1 |
| mcr.microsoft.com/ | fbf79e0fea59 | openssl openssl1.0 | 1.1.1-1ubuntu2.1~18.04.23+esm10 1.0.2n-1ubuntu5.13+esm6 | 1 |
| public.ecr.aws/ | af66e52f852a | openssl | 3.1.6-r0 | 1 |
| public.ecr.aws/ | ffc29318c5e9 | openssl | 3.1.6-r0 | 1 |
| public.ecr.aws/ | 873c49204b64 | openssl | 3.1.6-r0 | 1 |
| public.ecr.aws/ | f68901a54664 | openssl | 1:3.0.7-29.el9_4 | 1 |
| public.ecr.aws/ | ee9d973e3952 | openssl | no fix listed | 1 |
| public.ecr.aws/ | b1493760c716 | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | 34823c8abe00 | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | 5cd62142d6ed | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | f8fb4eea4071 | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | 71697b5ff713 | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | efcecf98b912 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm10 | 1 |
| public.ecr.aws/ | 573779e57fae | openssl | 1.1.1f-1ubuntu2.23 | 1 |
| public.ecr.aws/ | f74851ce31f5 | openssl | 3.0.15-1~deb12u1 | 1 |
| public.ecr.aws/ | 794b3bff9510 | openssl | 1:3.0.7-29.el9_4 | 1 |
| public.ecr.aws/ | 27f8de509169 | openssl | 3.0.15-1~deb12u1 | 1 |
| quay.io/ | 70fd7c00418d | openssl | 3.0.2-0ubuntu1.17 | 1 |
| quay.io/ | 578934444f04 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| quay.io/ | 70d138997acd | openssl | 1:3.0.7-29.el9_4 | 1 |
| quay.io/ | 7302e0c8e5a7 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | 3b036692d546 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | 5b6701d8fb31 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| quay.io/ | acaf37352569 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| quay.io/ | cdefc81c6b2e | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | 351d6685dc6f | openssl | 3.0.2-0ubuntu1.17 | 1 |
| quay.io/ | 96fac2482898 | openssl | 3.1.6-r0 | 1 |
| quay.io/ | 13aaae779248 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | 10df27bc5560 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | a3b9a07648b6 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | d9f0bec83ef0 | openssl | no fix listed | 1 |
| quay.io/ | a2d3a4c67b0f | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm10 | 1 |
| quay.io/ | 60950ef63764 | openssl | 3.0.2-0ubuntu1.17 | 1 |
| quay.io/ | d53cb940196c | openssl | 3.1.6-r0 | 1 |
| quay.io/ | 55330b1b60c1 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | bb40472e4ff5 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | 0cca71497e9e | openssl | 3.0.14-r0 | 1 |
| quay.io/ | 0dc38a87b844 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | ea838e5b4051 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | a8a9ec461034 | openssl | 1:1.1.1k-14.el8_6 | 1 |
| quay.io/ | cd36290dc849 | openssl | 3.1.6-r0 | 1 |
| quay.io/ | 93889c3d8a34 | openssl | 3.0.2-0ubuntu1.17 | 1 |