StackRadar

CVE-2024-7006

High

Advisory

Published 12 Aug 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
204
of 17,781 indexed, latest versions
Container images
212
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 204 of 17,781 indexed charts deploy, on 212 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+28 more4.0.3-7ubuntu0.11+esm14, 4.0.6-1ubuntu0.8+esm17, 4.0.9-5ubuntu0.10+esm7, 4.1.0+git191117-2ubuntu0.20.04.14+3 more195
libtiffrpm4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8, 4.0.9-29.el8_8+2 more0:4.0.9-33.el8_10, 0:4.4.0-12.el9_4.117
OSV records
DEBIAN-CVE-2024-7006RHSA-2024:8833RHSA-2024:8914UBUNTU-CVE-2024-7006
Also known as
USN-6997-1, USN-6997-2

Charts affected

204 by stars
ChartLatestAffected imagesRadar Score
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tiff@4.5.0-6
4.5.0-6+deb12u2

Open the chart page →

14,358
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
tiff@4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.10

Open the chart page →

13,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
tiff@4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.10

Open the chart page →

14,100
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2

Open the chart page →

7,673

Container images carrying it

212 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
twentycrm/twenty-postgres-spilo:latest2f78405a78be
tiff@4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.10
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
tiff@4.0.9-5ubuntu0.9
4.0.9-5ubuntu0.10+esm7
1
vlebediantsev/notes-admin-front:latest007c6670ff48
tiff@4.5.0-6
4.5.0-6+deb12u2
1
vlebediantsev/notes-project-front:latest945675fd2636
tiff@4.5.0-6
4.5.0-6+deb12u2
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
tiff@4.5.0-6
4.5.0-6+deb12u2
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
tiff@4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.10
1
xeladock/mysql_dns:latest4baf531453f1
tiff@4.3.0-6
4.3.0-6ubuntu0.10
1
xeladock/nginx2:latestc259a67b1dff
tiff@4.3.0-6
4.3.0-6ubuntu0.10
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.14
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
tiff@4.3.0-6
4.3.0-6ubuntu0.10
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
tiff@4.3.0-6
4.3.0-6ubuntu0.10
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
tiff@4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.10
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libtiff@4.0.9-17.el8
0:4.0.9-33.el8_10
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
tiff@4.3.0-6
4.3.0-6ubuntu0.10
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm7
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
tiff@4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
tiff@4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.14
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
tiff@4.5.0-6
4.5.0-6+deb12u2
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
tiff@4.5.0-6
4.5.0-6+deb12u2
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.