StackRadar

CVE-2024-7347

Medium

Advisory

Published 14 Aug 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.7
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
4 of 4
affected packages

NGINX MP4 module vulnerability

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
nginxbitnami1.25.5-0, 1.27.1-21.26.22
NGINX Open Sourcebitnami1.25.5-01.26.21
nginxdeb1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+3 more1.4.6-1ubuntu3.9+esm5, 1.18.0-0ubuntu1.6, 1.18.0-6ubuntu14.5, 1.22.1-9+deb12u211
nginxrpm1:1.20.1-13.el9, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0, 1:1.22.1-8.module+el9.5.0+22953+b175c265.11:1.22.1-8.module+el9.5.0+22953+b175c265.1, 1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.15
OSV records
BIT-nginx-2024-7347DEBIAN-CVE-2024-7347RHSA-2025:3261RHSA-2025:3262UBUNTU-CVE-2024-7347
Also known as
BIT-nginx-gateway-2024-7347, USN-7014-1, USN-7014-3

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
k10kastenVerified publisher9.0.51 of 23See more

k10 kasten 9.0.5

1 of the 23 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
gcr.io/kasten-images/frontend:9.0.54b36f413cabb
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.1

Open the chart page →

1,880
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
nginx@1.22.1-9
1.22.1-9+deb12u2

Open the chart page →

10,622
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nginx@1.18.0-0ubuntu1.2
1.18.0-0ubuntu1.6

Open the chart page →

12,422
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
nginx@1.4.6-1ubuntu3.8ppa1
1.4.6-1ubuntu3.9+esm5

Open the chart page →

70,895
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nginx@1.22.1-9
1.22.1-9+deb12u2

Open the chart page →

14,627
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nginx@1:1.20.1-13.el9
1:1.22.1-8.module+el9.5.0+22953+b175c265.1

Open the chart page →

55,666
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
nginx@1.18.0-0ubuntu1.4
1.18.0-0ubuntu1.6

Open the chart page →

25,122
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
nginx@1.18.0-6ubuntu14.4
1.18.0-6ubuntu14.5

Open the chart page →

4,077
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nginx@1.18.0-0ubuntu1.2
1.18.0-0ubuntu1.6

Open the chart page →

24,293
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
nginx@1.27.1-2
1.26.2

Open the chart page →

12,105
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
nginx@1.18.0-0ubuntu1.3
1.18.0-0ubuntu1.6

Open the chart page →

11,069
wjh-rechnerit-at-mOfficialVerified publisher1.0.41 of 1See more

wjh-rechner it-at-m 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nginx@1:1.22.1-5.module+el9.3.0.z+20438+032561a0
1:1.22.1-8.module+el9.5.0+22953+b175c265.1

Open the chart page →

3,460
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.1

Open the chart page →

7,310
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
nginx@1.18.0-0ubuntu1.3
1.18.0-0ubuntu1.6

Open the chart page →

22,084
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
nginx@1.25.5-0
NGINX Open Source@1.25.5-0
1.26.2
1.26.2

Open the chart page →

6,282
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.1

Open the chart page →

3,781
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2024-7347.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.5
xeladock/nginx2:latestc259a67b1dff
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.5

Open the chart page →

17,461

Container images carrying it

18 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
allegroai/clearml:2.0.0-613713ae38f7daf
nginx@1.22.1-9
1.22.1-9+deb12u2
1
bitnamilegacy/nginx:1.27.1934d1acd5ca8
nginx@1.27.1-2
1.26.2
1
fnzv/dump1090:latestb3079b95c336
nginx@1.18.0-6ubuntu14.4
1.18.0-6ubuntu14.5
1
galaxy/galaxy-stable:v18.018e577a626dfd
nginx@1.4.6-1ubuntu3.8ppa1
1.4.6-1ubuntu3.9+esm5
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
nginx@1.18.0-0ubuntu1.3
1.18.0-0ubuntu1.6
1
seafileltd/seafile-mc:9.0.106693911bcc40
nginx@1.18.0-0ubuntu1.4
1.18.0-0ubuntu1.6
1
seafileltd/seafile-mc:9.0.97ac833196f60
nginx@1.18.0-0ubuntu1.3
1.18.0-0ubuntu1.6
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nginx@1.18.0-0ubuntu1.2
1.18.0-0ubuntu1.6
1
xeladock/mysql_dns:latest4baf531453f1
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.5
1
xeladock/nginx2:latestc259a67b1dff
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.5
1
gcr.io/kasten-images/frontend:9.0.54b36f413cabb
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.1
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nginx@1:1.20.1-13.el9
1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nginx@1:1.22.1-5.module+el9.3.0.z+20438+032561a0
1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nginx@1.18.0-0ubuntu1.2
1.18.0-0ubuntu1.6
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nginx@1.22.1-9
1.22.1-9+deb12u2
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
nginx@1.25.5-0
NGINX Open Source@1.25.5-0
1.26.2
1.26.2
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.1
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
1:1.24.0-4.module+el9.5.0+22954+e2d70a1c.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.