CVE-2025-23083
HighAdvisory
Published 22 Jan 2025In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.7
- base score, highest
- EPSS
- 0.004
- 36th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2
- of 17,781 indexed, latest versions
- Container images
- 3
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Red Hat Security Advisory: nodejs:20 security update
Carried by container images the latest versions of 2 of 17,781 indexed charts deploy, on 3 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nodejsrpm | 1:20.12.2-2.module+el9.4.0+21731+46b5b8a7, 1:20.16.0-1.module+el9.4.0+22197+9e60f127 | 1:20.18.2-1.module+el9.4.0+22789+7c201776 | 2 |
| nodejsdeb | 18.20.8-1nodesource1 | 20.18.2+dfsg-1 | 1 |
- OSV records
- DEBIAN-CVE-2025-23083RHSA-2025:1522
Charts affected
2 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| kubiya-runnerkubiya-helm-chartsOfficialVerified publisher | 0.9.4 | 1 of 9See more | 20,204 |
| chatbot-ai-sampleopenshift | 0.1.6 | 2 of 4See more | 18,922 |
Container images carrying it
3 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 757bdd779345 | nodejs | 20.18.2+dfsg-1 | 1 |
| quay.io/ | 70d138997acd | nodejs | 1:20.18.2-1.module+el9.4.0+22789+7c201776 | 1 |
| quay.io/ | 59fe607dfdf2 | nodejs | 1:20.18.2-1.module+el9.4.0+22789+7c201776 | 1 |