GHSA-5x4g-q5rc-36jp
LowAdvisory
Published 3 Feb 2024In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 2.0
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 72
- of 17,781 indexed, latest versions
- Container images
- 59
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Insecure ciphers are allowed by default in go.etcd.io/etcd
Carried by container images the latest versions of 72 of 17,781 indexed charts deploy, on 59 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| go.etcd.io/ | v0.0.0-20190215181705-784daa04988c, v0.0.0-20190228193606-a943ad0ee4c9, v0.0.0-20191023171146-3cf2f69b5738, v0.0.0-20200401174654-e694b7bb0875+10 more | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 56 |
| go.etcd.io/ | v3.0.0-20210928084031-3df272774672 | 3.3.23 | 3 |
- OSV records
- GHSA-5x4g-q5rc-36jpGO-2024-2527
Charts affected
72 by stars
Container images carrying it
59 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | ded797477896 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | d6fd2a9e3273 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | 5d1c2cf4c538 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | 9663f06adcb1 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | e045b26eb6df | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | 4fbd63194674 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | 34de6387233b | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | 6d56f69b15a3 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |
| quay.io/ | 6722d5041b47 | go.etcd.io/ | 0.5.0-alpha.5.0.20221102000833-1f054980bc27 | 1 |