StackRadar

CVE-2024-7006

High

Advisory

Published 12 Aug 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,787 indexed, latest versions
Container images
214
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libtiff security update

Carried by container images the latest versions of 206 of 17,787 indexed charts deploy, on 214 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+29 more4.0.3-7ubuntu0.11+esm14, 4.0.6-1ubuntu0.8+esm17, 4.0.9-5ubuntu0.10+esm7, 4.1.0+git191117-2ubuntu0.20.04.14+3 more197
libtiffrpm4.0.9-17.el8, 4.0.9-18.el8, 4.0.9-28.el8_8, 4.0.9-29.el8_8+2 more0:4.0.9-33.el8_10, 0:4.4.0-12.el9_4.117
OSV records
DEBIAN-CVE-2024-7006RHSA-2024:8833RHSA-2024:8914UBUNTU-CVE-2024-7006
Also known as
USN-6997-1, USN-6997-2

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2

Open the chart page →

17,348
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
tiff@4.5.1+git230720-4ubuntu2
4.5.1+git230720-4ubuntu2.2

Open the chart page →

45,392
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tiff@4.5.0-6
4.5.0-6+deb12u2

Open the chart page →

14,383
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
tiff@4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.10

Open the chart page →

13,563
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
tiff@4.3.0-6ubuntu0.9
4.3.0-6ubuntu0.10

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2024-7006.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2

Open the chart page →

7,685

Container images carrying it

214 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
tiff@4.0.6-1ubuntu0.4
4.0.6-1ubuntu0.8+esm17
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
tiff@4.0.6-1ubuntu0.6
4.0.6-1ubuntu0.8+esm17
4
library/nginx:1.27.1287ff321f9e3
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
4
ciscolabs/rtsp-client:latesta7b60ec88285
tiff@4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.14
3
ciscolabs/rtsp-server:latestb59fc10bb821
tiff@4.1.0+git191117-2ubuntu0.20.04.5
4.1.0+git191117-2ubuntu0.20.04.14
3
library/nginx:1.25:1.25.5a484819eb602
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
tiff@4.0.6-1ubuntu0.5
4.0.6-1ubuntu0.8+esm17
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
tiff@4.5.0-6
4.5.0-6+deb12u2
3
quay.io/devtron/ai-agent:0.0.16545dac92173
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
tiff@4.5.1+git230720-4ubuntu2
4.5.1+git230720-4ubuntu2.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
tiff@4.5.0-6
4.5.0-6+deb12u2
2
library/nginx:1.27.098f8ec75657d
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
2
library/python:3.7eedf63967cdb
tiff@4.5.0-6
4.5.0-6+deb12u2
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
tiff@4.5.0-6
4.5.0-6+deb12u2
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
tiff@4.5.0-6
4.5.0-6+deb12u2
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
tiff@4.3.0-6ubuntu0.1
4.3.0-6ubuntu0.10
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
2
5200710/hadoop:3.2.3-java8092d3088a5fb
tiff@4.1.0+git191117-2ubuntu0.20.04.11
4.1.0+git191117-2ubuntu0.20.04.14
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
akaunting/akaunting:3.0.1552811b36ec3a
tiff@4.5.0-6
4.5.0-6+deb12u2
1
allegroai/clearml:2.0.0-613713ae38f7daf
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
aristidetm/basic-notebook:3.6.5469dbc951224
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
assistiot/open_api_backend:1.1.230812ba93555
tiff@4.3.0-6ubuntu0.7
4.3.0-6ubuntu0.10
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
tiff@4.5.0-6
4.5.0-6+deb12u2
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
tiff@4.1.0+git191117-2ubuntu0.20.04.12
4.1.0+git191117-2ubuntu0.20.04.14
1
avinash263/pyredis263:latestaa2b8727f1a6
tiff@4.5.0-6
4.5.0-6+deb12u2
1
avzini/web-app:latestf40b30210ed0
tiff@4.5.0-6
4.5.0-6+deb12u2
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.14
1
bnjbvr/kresus:0.22.137e216b182c8
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.14
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
castopod/castopod:1.12.101fd37280cbb2
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
cheyang/distributed-tf:1.6.046cc34755493
tiff@4.0.6-1ubuntu0.2
4.0.6-1ubuntu0.8+esm17
1
codetogether/codetogether:latest4348c8a38752
libtiff@4.4.0-12.el9
0:4.4.0-12.el9_4.1
1
countly/countly-server:25.05.4e3c238248f99
tiff@4.1.0+git191117-2ubuntu0.20.04.13
4.1.0+git191117-2ubuntu0.20.04.14
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
tiff@4.5.0-6
4.5.0-6+deb12u2
1
dannielkil/book-frontend:latest937993927694
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
daskdev/dask-notebook:1.1.0052630f5ca04
tiff@4.0.9-5ubuntu0.1
4.0.9-5ubuntu0.10+esm7
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.14
1
dragonflyoss/client:v0.1.82edf3e921f4e0
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm7
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.10+esm7
1
emqx/ecp-ui:2.5.1e33e9816f147
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
felipecs8/app-db-connection-test:v129e06c9c6385
tiff@4.5.0-6+deb12u1
4.5.0-6+deb12u2
1
firefart/requesttracker:5.0.40d6249906d8c
tiff@4.5.0-6
4.5.0-6+deb12u2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.