StackRadar

CVE-2025-23090

Unscored

Advisory

Published 27 Jan 2025In the index since 22 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 17,828 indexed, latest versions
Container images
4
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 4 of 17,828 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
nodebitnami20.4.0-0, 20.5.1-1, 20.9.0-0, 20.12.0-020.18.24
Node.jsbitnami20.4.0, 20.5.1, 20.9.0, 20.12.0-020.18.24
OSV records
BIT-node-2025-23090
Also known as
BIT-node-min-2025-23090

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
deployment-servicekrateo1.2.591 of 1See more

deployment-service krateo 1.2.59

1 of the 1 container images this version deploys carry CVE-2025-23090.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/deployment-service:1.2.59da9f93f2f731
node@20.12.0-0
Node.js@20.12.0-0
20.18.2
20.18.2

Open the chart page →

9,761
git-servicekrateo1.0.131 of 1See more

git-service krateo 1.0.13

1 of the 1 container images this version deploys carry CVE-2025-23090.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/git-service:1.0.13c22f183fedf0
node@20.4.0-0
Node.js@20.4.0
20.18.2
20.18.2

Open the chart page →

5,451
keptn-servicekrateo1.0.121 of 1See more

keptn-service krateo 1.0.12

1 of the 1 container images this version deploys carry CVE-2025-23090.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/keptn-service:1.0.12f9fef2435636
node@20.9.0-0
Node.js@20.9.0
20.18.2
20.18.2

Open the chart page →

4,673
krateo-remote-serverkrateo0.2.41 of 1See more

krateo-remote-server krateo 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-23090.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/krateo-remote-server:0.2.40df58c99cc6f
node@20.5.1-1
Node.js@20.5.1
20.18.2
20.18.2

Open the chart page →

4,890

Container images carrying it

4 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/krateoplatformops/deployment-service:1.2.59da9f93f2f731
node@20.12.0-0
Node.js@20.12.0-0
20.18.2
20.18.2
1
ghcr.io/krateoplatformops/git-service:1.0.13c22f183fedf0
node@20.4.0-0
Node.js@20.4.0
20.18.2
20.18.2
1
ghcr.io/krateoplatformops/keptn-service:1.0.12f9fef2435636
node@20.9.0-0
Node.js@20.9.0
20.18.2
20.18.2
1
ghcr.io/krateoplatformops/krateo-remote-server:0.2.40df58c99cc6f
node@20.5.1-1
Node.js@20.5.1
20.18.2
20.18.2
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.