GHSA-x565-32qp-m3vf
MediumAdvisory
Published 11 Apr 2024In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.3
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 9
- of 17,781 indexed, latest versions
- Container images
- 10
- deployed by those charts
- Fix available
- 1 of 1
- affected package
phin may include sensitive headers in subsequent requests after redirect
Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 10 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| phinnpm | 2.9.3 | 3.7.1 | 10 |
- OSV records
- GHSA-x565-32qp-m3vf
Charts affected
9 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| portraitportraitVerified publisher | 0.2.13 | 1 of 8See more | 31,844 |
| linkwardenadnoctemVerified publisher | 0.5.1 | 1 of 2See more | 3,820 |
| countlychristianhuthVerified publisher | 5.2.1 | 2 of 3See more | 7,295 |
| quickchartcowboysysopVerified publisher | 5.0.0 | 1 of 1See more | 5,488 |
| picolorsealenn | 0.1.0 | 1 of 1See more | 576 |
| keyrockfiware | 0.8.7 | 1 of 1See more | 3,159 |
| countlyhelmforgeVerified publisher | 1.2.6 | 1 of 3See more | 18,813 |
| image-storage-servicejtektVerified publisher | 0.4.3 | 1 of 4See more | 22,589 |
| ohmyformkrzwiatrzyk | 0.0.1 | 1 of 1See more | 4,230 |
Container images carrying it
10 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| countly/ | f4cc7447c4f5 | phin | 3.7.1 | 1 |
| countly/ | e3c238248f99 | phin | 3.7.1 | 1 |
| countly/ | 2acbc11499b6 | phin | 3.7.1 | 1 |
| ealen/ | 3cb01dcbf652 | phin | 3.7.1 | 1 |
| fiware/ | a1b6ed4ae84f | phin | 3.7.1 | 1 |
| ianw/ | dc49dd460c37 | phin | 3.7.1 | 1 |
| ohmyform/ | afe53f4acdb1 | phin | 3.7.1 | 1 |
| treskon/ | e7970783bc8d | phin | 3.7.1 | 1 |
| ghcr.io/ | 0664c28a039b | phin | 3.7.1 | 1 |
| public.ecr.aws/ | b1493760c716 | phin | 3.7.1 | 1 |