Vulnerability Reportnginxdemos/hello:0.2-plain-text

nginxdemos/hello:0.2-plain-text
DIGESTsha256:bf81fd9487414f40996acbde843e56c499e94ec6deba4f032492bc2e711842e9

Executive Summary

Threat Score
100/100DANGEROUS
Reputation
RELIABLE

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2023-44487 (HTTP/2 Rapid Reset) to cause a denial of service, or leverage CVE-2018-25032 in zlib to trigger memory corruption, potentially leading to code execution. Note that CVE-2023-0286 only applies if CRL checking is enabled, which is non-default for nginx. Disabling HTTP/2 would fully mitigate CVE-2023-44487, but at a significant performance cost.

Vulnerabilities

Vulnerability Log

115 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2023-44487CRITICAL9.75
nghttp2-libs
1.46.0-r0
fixed in 1.46.0-r2
100.0%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2018-25032HIGH7.8
zlib
1.2.11-r3
fixed in 1.2.12-r0
51.7%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-0286HIGH7.7
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1t-r0
59.5%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-0286HIGH7.7
libssl1.1
1.1.1n-r0
fixed in 1.1.1t-r0
59.5%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-0464HIGH7.5
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1t-r2
3.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-0215HIGH7.5
libssl1.1
1.1.1n-r0
fixed in 1.1.1t-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-0464HIGH7.5
libssl1.1
1.1.1n-r0
fixed in 1.1.1t-r2
3.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-35945HIGH7.5
nghttp2-libs
1.46.0-r0
fixed in 1.46.0-r1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2022-4304MEDIUM6.79
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1t-r0
16.2%
High Exploitation Risk
Directly Exposed
CVE-2022-4304MEDIUM6.79
libssl1.1
1.1.1n-r0
fixed in 1.1.1t-r0
16.2%
High Exploitation Risk
Directly Exposed
CVE-2023-2650MEDIUM6.76
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1u-r0
77.9%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2023-2650MEDIUM6.76
libssl1.1
1.1.1n-r0
fixed in 1.1.1u-r0
77.9%
Actively Exploited
Directly ExposedContext importance: MEDIUM
CVE-2022-29824MEDIUM6.5
libxml2
2.9.13-r0
fixed in 2.9.14-r0
3.4%
Low-Moderate Risk
Directly Exposed
CVE-2023-1999MEDIUM6.38
libwebp
1.2.2-r0
fixed in 1.2.2-r1
1.0%
Theoretical Threat
Directly Exposed
CVE-2022-41409MEDIUM6.38
pcre2
10.39-r0
fixed in 10.42-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2022-2097MEDIUM5.3
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1q-r0
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-0465MEDIUM5.3
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1t-r2
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-3446MEDIUM5.3
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1u-r2
5.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-3817MEDIUM5.3
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1v-r0
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1w-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2022-2097MEDIUM5.3
libssl1.1
1.1.1n-r0
fixed in 1.1.1q-r0
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-0465MEDIUM5.3
libssl1.1
1.1.1n-r0
fixed in 1.1.1t-r2
1.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-3446MEDIUM5.3
libssl1.1
1.1.1n-r0
fixed in 1.1.1u-r2
5.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-3817MEDIUM5.3
libssl1.1
1.1.1n-r0
fixed in 1.1.1v-r0
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
libssl1.1
1.1.1n-r0
fixed in 1.1.1w-r1
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-27533MEDIUM5.28
curl
7.80.0-r0
fixed in 8.0.1-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-27534MEDIUM5.28
curl
7.80.0-r0
fixed in 8.0.1-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-27533MEDIUM5.28
libcurl
7.80.0-r0
fixed in 8.0.1-r0
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-27534MEDIUM5.28
libcurl
7.80.0-r0
fixed in 8.0.1-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-43551MEDIUM5.17
curl
7.80.0-r0
fixed in 7.80.0-r5
17.0%
High Exploitation Risk
Post-Exploit
CVE-2022-43551MEDIUM5.17
libcurl
7.80.0-r0
fixed in 7.80.0-r5
17.0%
High Exploitation Risk
Post-Exploit
CVE-2022-22576MEDIUM4.86
curl
7.80.0-r0
fixed in 7.80.0-r1
1.9%
Low-Moderate Risk
Post-Exploit
CVE-2022-42915MEDIUM4.86
curl
7.80.0-r0
fixed in 7.80.0-r4
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2022-22576MEDIUM4.86
libcurl
7.80.0-r0
fixed in 7.80.0-r1
1.9%
Low-Moderate Risk
Post-Exploit
CVE-2022-42915MEDIUM4.86
libcurl
7.80.0-r0
fixed in 7.80.0-r4
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2023-23914MEDIUM4.64
curl
7.80.0-r0
fixed in 7.80.0-r6
0.9%
Theoretical Threat
Post-Exploit
CVE-2023-23914MEDIUM4.64
libcurl
7.80.0-r0
fixed in 7.80.0-r6
0.9%
Theoretical Threat
Post-Exploit
CVE-2023-38545MEDIUM4.58
curl
7.80.0-r0
fixed in 8.4.0-r0
78.5%
Actively Exploited
Post-Exploit
CVE-2023-38545MEDIUM4.58
libcurl
7.80.0-r0
fixed in 8.4.0-r0
78.5%
Actively Exploited
Post-Exploit
CVE-2022-27775MEDIUM4.5
curl
7.80.0-r0
fixed in 7.80.0-r1
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2022-27780MEDIUM4.5
curl
7.80.0-r0
fixed in 7.80.0-r2
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-27781MEDIUM4.5
curl
7.80.0-r0
fixed in 7.80.0-r2
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2022-27782MEDIUM4.5
curl
7.80.0-r0
fixed in 7.80.0-r2
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2022-42916MEDIUM4.5
curl
7.80.0-r0
fixed in 7.80.0-r4
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-28319MEDIUM4.5
curl
7.80.0-r0
fixed in 8.1.0-r0
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-27775MEDIUM4.5
libcurl
7.80.0-r0
fixed in 7.80.0-r1
2.8%
Low-Moderate Risk
Post-Exploit
CVE-2022-27780MEDIUM4.5
libcurl
7.80.0-r0
fixed in 7.80.0-r2
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-27781MEDIUM4.5
libcurl
7.80.0-r0
fixed in 7.80.0-r2
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2022-27782MEDIUM4.5
libcurl
7.80.0-r0
fixed in 7.80.0-r2
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2022-42916MEDIUM4.5
libcurl
7.80.0-r0
fixed in 7.80.0-r4
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-28319MEDIUM4.5
libcurl
7.80.0-r0
fixed in 8.1.0-r0
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-32206MEDIUM4.48
curl
7.80.0-r0
fixed in 7.80.0-r2
32.0%
High Exploitation Risk
Post-Exploit
CVE-2022-32206MEDIUM4.48
libcurl
7.80.0-r0
fixed in 7.80.0-r2
32.0%
High Exploitation Risk
Post-Exploit
CVE-2023-4863MEDIUM4.12
libwebp
1.2.2-r0
fixed in 1.2.2-r2
99.7%
Actively Exploited
Post-Exploit
CVE-2022-37434MEDIUM4.06
zlib
1.2.11-r3
fixed in 1.2.12-r2
15.9%
High Exploitation Risk
Post-Exploit
CVE-2022-27776LOW3.9
curl
7.80.0-r0
fixed in 7.80.0-r1
3.4%
Low-Moderate Risk
Post-Exploit
CVE-2023-23916LOW3.9
curl
7.80.0-r0
fixed in 7.80.0-r6
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW3.9
curl
7.80.0-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2022-27776LOW3.9
libcurl
7.80.0-r0
fixed in 7.80.0-r1
3.4%
Low-Moderate Risk
Post-Exploit
CVE-2023-23916LOW3.9
libcurl
7.80.0-r0
fixed in 7.80.0-r6
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW3.9
libcurl
7.80.0-r0
fixed in 8.5.0-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2022-32208LOW3.54
curl
7.80.0-r0
fixed in 7.80.0-r2
5.6%
Low-Moderate Risk
Post-Exploit
CVE-2022-43552LOW3.54
curl
7.80.0-r0
fixed in 7.80.0-r5
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-27535LOW3.54
curl
7.80.0-r0
fixed in 8.0.1-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-27536LOW3.54
curl
7.80.0-r0
fixed in 8.0.1-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-27537LOW3.54
curl
7.80.0-r0
fixed in 8.0.1-r0
1.9%
Low-Moderate Risk
Post-Exploit
CVE-2023-28320LOW3.54
curl
7.80.0-r0
fixed in 8.1.0-r0
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-28321LOW3.54
curl
7.80.0-r0
fixed in 8.1.0-r0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2022-32208LOW3.54
libcurl
7.80.0-r0
fixed in 7.80.0-r2
5.6%
Low-Moderate Risk
Post-Exploit
CVE-2022-43552LOW3.54
libcurl
7.80.0-r0
fixed in 7.80.0-r5
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-27535LOW3.54
libcurl
7.80.0-r0
fixed in 8.0.1-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-27536LOW3.54
libcurl
7.80.0-r0
fixed in 8.0.1-r0
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-27537LOW3.54
libcurl
7.80.0-r0
fixed in 8.0.1-r0
1.9%
Low-Moderate Risk
Post-Exploit
CVE-2023-28320LOW3.54
libcurl
7.80.0-r0
fixed in 8.1.0-r0
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-28321LOW3.54
libcurl
7.80.0-r0
fixed in 8.1.0-r0
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2022-32207LOW3.53
curl
7.80.0-r0
fixed in 7.80.0-r2
5.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-32221LOW3.53
curl
7.80.0-r0
fixed in 7.80.0-r4
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2022-27404LOW3.53
freetype
2.11.0-r0
fixed in 2.11.1-r1
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2022-32207LOW3.53
libcurl
7.80.0-r0
fixed in 7.80.0-r2
5.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-32221LOW3.53
libcurl
7.80.0-r0
fixed in 7.80.0-r4
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-38039LOW3.51
curl
7.80.0-r0
fixed in 8.3.0-r0
62.2%
Actively Exploited
Post-Exploit
CVE-2023-38039LOW3.51
libcurl
7.80.0-r0
fixed in 8.3.0-r0
62.2%
Actively Exploited
Post-Exploit
CVE-2022-27774LOW3.42
curl
7.80.0-r0
fixed in 7.80.0-r1
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2022-27774LOW3.42
libcurl
7.80.0-r0
fixed in 7.80.0-r1
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-23915LOW3.31
curl
7.80.0-r0
fixed in 7.80.0-r6
0.9%
Theoretical Threat
Post-Exploit
CVE-2023-23915LOW3.31
libcurl
7.80.0-r0
fixed in 7.80.0-r6
0.9%
Theoretical Threat
Post-Exploit
CVE-2023-27538LOW3.3
curl
7.80.0-r0
fixed in 8.0.1-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-27538LOW3.3
libcurl
7.80.0-r0
fixed in 8.0.1-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-1586LOW3.28
pcre2
10.39-r0
fixed in 10.40-r0
3.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-1587LOW3.28
pcre2
10.39-r0
fixed in 10.40-r0
2.4%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
curl
7.80.0-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
libcurl
7.80.0-r0
fixed in 8.5.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-28391LOW3.17
busybox
1.34.1-r4
fixed in 1.34.1-r5
3.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-28391LOW3.17
ssl_client
1.34.1-r4
fixed in 1.34.1-r5
3.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-1271LOW3.17
xz-libs
5.2.5-r0
fixed in 5.2.5-r1
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2022-4450LOW3.1
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1t-r0
20.4%
High Exploitation Risk
Post-Exploit
CVE-2022-4450LOW3.1
libssl1.1
1.1.1n-r0
fixed in 1.1.1t-r0
20.4%
High Exploitation Risk
Post-Exploit
CVE-2022-40303LOW3.1
libxml2
2.9.13-r0
fixed in 2.9.14-r2
24.2%
High Exploitation Risk
Post-Exploit
CVE-2022-32205LOW2.97
curl
7.80.0-r0
fixed in 7.80.0-r2
26.9%
High Exploitation Risk
Post-Exploit
CVE-2022-32205LOW2.97
libcurl
7.80.0-r0
fixed in 7.80.0-r2
26.9%
High Exploitation Risk
Post-Exploit
CVE-2022-40304LOW2.81
libxml2
2.9.13-r0
fixed in 2.9.14-r2
6.8%
Low-Moderate Risk
Post-Exploit
CVE-2022-27405LOW2.7
freetype
2.11.0-r0
fixed in 2.11.1-r2
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-27406LOW2.7
freetype
2.11.0-r0
fixed in 2.11.1-r2
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-0215LOW2.7
libcrypto1.1
1.1.1n-r0
fixed in 1.1.1t-r0
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2022-2309LOW2.7
libxml2
2.9.13-r0
fixed in 2.9.14-r1
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-35252LOW2.22
curl
7.80.0-r0
fixed in 7.80.0-r3
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2023-28322LOW2.22
curl
7.80.0-r0
fixed in 8.1.0-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-38546LOW2.22
curl
7.80.0-r0
fixed in 8.4.0-r0
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-35252LOW2.22
libcurl
7.80.0-r0
fixed in 7.80.0-r3
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2023-28322LOW2.22
libcurl
7.80.0-r0
fixed in 8.1.0-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-38546LOW2.22
libcurl
7.80.0-r0
fixed in 8.4.0-r0
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-29491NONE0
ncurses-libs
6.3_p20211120-r0
fixed in 6.3_p20211120-r2
0.9%
Theoretical Threat
Not Applicable
CVE-2023-29491NONE0
ncurses-terminfo-base
6.3_p20211120-r0
fixed in 6.3_p20211120-r2
0.9%
Theoretical Threat
Not Applicable
CVE-2022-29458NONE0
ncurses-libs
6.3_p20211120-r0
fixed in 6.3_p20211120-r1
1.3%
Low-Moderate Risk
Not Applicable
CVE-2022-29458NONE0
ncurses-terminfo-base
6.3_p20211120-r0
fixed in 6.3_p20211120-r1
1.3%
Low-Moderate Risk
Not Applicable