StackRadar

CVE-2024-6387

High

Advisory

Published 1 Jul 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.995
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
93
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 93 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:8.9p1-3, 1:8.9p1-3ubuntu0.1, 1:8.9p1-3ubuntu0.4, 1:8.9p1-3ubuntu0.6+4 more1:8.9p1-3ubuntu0.10, 1:9.2p1-2+deb12u356
opensshapk9.1_p1-r1, 9.1_p1-r2, 9.3_p1-r3, 9.3_p2-r0+3 more9.1_p1-r6, 9.3_p2-r2, 9.6_p1-r1, 9.7_p1-r421
opensshrpm8.7p1-30.el9_2, 8.7p1-38.el90:8.7p1-38.el9_4.12
OSV records
ALPINE-CVE-2024-6387DEBIAN-CVE-2024-6387RHSA-2024:4312UBUNTU-CVE-2024-6387
Also known as
DSA-5724-1, RHSA-2024:4340, USN-6859-1

Charts affected

93 by stars
ChartLatestAffected imagesRadar Score
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
openssh@9.1_p1-r2
9.1_p1-r6

Open the chart page →

2,295
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3

Open the chart page →

13,686
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
openssh@9.3_p2-r1
9.3_p2-r2

Open the chart page →

3,430
smilencsaVerified publisher1.1.04 of 23See more

smile ncsa 1.1.0

4 of the 23 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
socialmediamacroscope/preprocessing:0.1.3ca863306314b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

109,294
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

15,187
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssh@8.7p1-38.el9
0:8.7p1-38.el9_4.1

Open the chart page →

18,922
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssh@8.7p1-30.el9_2
0:8.7p1-38.el9_4.1

Open the chart page →

8,599
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
library/docker:23.0.1-dindd9a0fd8bdd15
openssh@9.1_p1-r2
9.1_p1-r6

Open the chart page →

4,237
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

12,350
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

16,196
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

12,912
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3

Open the chart page →

6,565
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

8,169
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
openssh@9.3_p2-r0
9.3_p2-r2

Open the chart page →

4,215
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

14,537
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

12,566
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

12,566
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

7,431
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssh@1:8.9p1-3ubuntu0.1
1:8.9p1-3ubuntu0.10

Open the chart page →

12,949
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3

Open the chart page →

68,240
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3

Open the chart page →

32,902
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

16,620
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

10,209
hermitcrabseal-ioVerified publisher0.1.41 of 2See more

hermitcrab seal-io 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
openssh@9.3_p2-r0
9.3_p2-r2

Open the chart page →

4,881
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
openssh@9.3_p2-r1
9.3_p2-r2

Open the chart page →

3,337
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
openssh@9.3_p2-r0
9.3_p2-r2

Open the chart page →

2,863
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

20,223
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

13,390
convert-datasvtechVerified publisher0.13.21 of 3See more

convert-data svtech 0.13.2

1 of the 3 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
openssh@1:8.9p1-3ubuntu0.7
1:8.9p1-3ubuntu0.10

Open the chart page →

7,588
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.10

Open the chart page →

12,048
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.10

Open the chart page →

12,048
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
openssh@9.3_p2-r0
9.3_p2-r2

Open the chart page →

4,212
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.10

Open the chart page →

20,270
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
openssh@9.6_p1-r0
9.6_p1-r1

Open the chart page →

2,806
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3

Open the chart page →

14,358
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2024-6387.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3

Open the chart page →

5,542

Container images carrying it

79 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
substratusai/verba:v0.4.0-baseURL261695be635eb
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
openssh@1:8.9p1-3ubuntu0.7
1:8.9p1-3ubuntu0.10
1
teknas09/bird-pod:latest12a1fa85c4aa
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3
1
theradius/loggia:0.463ba348546ec
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3
1
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
vlebediantsev/notes-admin-front:latest007c6670ff48
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
vlebediantsev/notes-project-front:latest945675fd2636
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
openssh@9.7_p1-r3
9.7_p1-r4
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
openssh@9.3_p2-r0
9.3_p2-r2
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
openssh@9.3_p2-r0
9.3_p2-r2
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u3
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.10
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.10
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.10
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.10
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
openssh@9.1_p1-r2
9.1_p1-r6
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssh@8.7p1-38.el9
0:8.7p1-38.el9_4.1
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssh@8.7p1-30.el9_2
0:8.7p1-38.el9_4.1
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u3
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.