CVE-2024-9681
MediumAdvisory
Published 6 Nov 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.020
- 79th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 502
- of 17,787 indexed, latest versions
- Container images
- 502
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
curl-8.11.0-1.1 on GA media
Carried by container images the latest versions of 502 of 17,787 indexed charts deploy, on 502 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 7.81.0-1ubuntu1.2, 7.81.0-1ubuntu1.3, 7.81.0-1ubuntu1.4, 7.81.0-1ubuntu1.6+19 more | 7.81.0-1ubuntu1.19, 7.88.1-10+deb12u9, 8.5.0-2ubuntu10.5 | 309 |
| curlapk | 8.0.1-r2, 8.1.0-r0, 8.1.1-r1, 8.1.2-r0+13 more | 8.11.0-r0 | 191 |
| curlrpm | 7.60.0-lp151.5.6.1 | 8.11.0-1.1 | 2 |
- OSV records
- ALPINE-CVE-2024-9681CGA-6vgx-rqv6-p48qDEBIAN-CVE-2024-9681UBUNTU-CVE-2024-9681openSUSE-SU-2024:14476-1
- Also known as
- CGA-f97r-fwm9-2xxp, USN-7104-1
Charts affected
502 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| prometheusalertygqygq2Verified publisher | 1.0.0 | 1 of 1See more | 1,611 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,589 |
Container images carrying it
502 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.k8s.io/ | d56f135b6462 | curl | 8.11.0-r0 | 1 |
| registry.k8s.io/ | e24f39d3eed6 | curl | 8.11.0-r0 | 1 |