business-api-ecosystem Helm chart
fiwareScored 14 Sept 2026
A Helm chart for running the FIWARE business API ecosystem (FIWARE Marketplace) on Kubernetes
Latest 1.1.0 2 months agodeploys tag 11.7.0 0Artifact Hub
business-api-ecosystem 1.1.0 deploys 4 container images: bitnamilegacy/mongodb, fiware/biz-ecosystem-charging-backend, library/busybox and fiware/biz-ecosystem-logic-proxy. Across them, 4,380 findings — 66 critical, 60 high — 58 on CISA KEV. The highest contribution is UBUNTU-CVE-2025-24201 in webkit2gtk 2.38.6-0ubuntu0.20.04.1, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnamilegacy/ | 3.6.21 | 0024149 | 1,926 |
| fiware/ | 11.7.0 | 65551,1091,906 | 50,775 |
| library/ | latest | 0000 | 0 |
| fiware/ | 11.20.3 | 15183878 | 11,788 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-72xf-g2v4-qvf3 | tough-cookie | 4.1.3 |
| Medium | UBUNTU-CVE-2022-2097 | openssl | 1.1.1f-1ubuntu2.fips.16 |
| Medium | UBUNTU-CVE-2024-9401 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2020-12406 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2020-12409 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2024-27820 | webkit2gtk | no fix listed |
| Medium | UBUNTU-CVE-2024-27820 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2021-23972 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2021-29966 | mozjs68 | no fix listed |
| Medium | DEBIAN-CVE-2026-56379 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u8 |
| Medium | DEBIAN-CVE-2025-13836 | python3.11 | 3.11.2-6+deb12u7 |
| Medium | UBUNTU-CVE-2025-13836 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm4 |
| Medium | UBUNTU-CVE-2021-29977 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2021-29990 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2024-23214 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2024-23214 | webkit2gtk | no fix listed |
| Medium | UBUNTU-CVE-2017-7064 | qtwebkit-opensource-src | no fix listed |
| Medium | DEBIAN-CVE-2026-6473 | postgresql-15 | 15.19-0+deb12u1 |
| Medium | UBUNTU-CVE-2020-15675 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2017-2508 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2026-4176 | perl | no fix listed |
| Medium | UBUNTU-CVE-2021-29981 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2021-30954 | qtwebkit-opensource-src | no fix listed |
| Medium | DLA-2786-1 | nghttp2 | 1.18.1-1+deb9u2 |
| Medium | UBUNTU-CVE-2021-38510 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2024-54479 | webkit2gtk | no fix listed |
| Medium | UBUNTU-CVE-2024-54479 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2022-22738 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2024-8384 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2020-27918 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2026-18924 | curl | no fix listed |
| Medium | GHSA-j8r2-6x86-q33q | requests | 2.31.0 |
| Medium | UBUNTU-CVE-2026-1519 | bind9 | no fix listed |
| Medium | UBUNTU-CVE-2023-5724 | mozjs68 | no fix listed |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | UBUNTU-CVE-2021-29986 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2022-26719 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2022-34485 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2022-34484 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2023-37369 | qtbase-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2026-4689 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2023-5678 | openssl | 1.1.1f-1ubuntu2.fips.21 |
| Medium | UBUNTU-CVE-2017-7038 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2022-23639 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2022-22759 | mozjs68 | no fix listed |
| Medium | UBUNTU-CVE-2023-40451 | webkit2gtk | no fix listed |
| Medium | UBUNTU-CVE-2023-40451 | qtwebkit-opensource-src | no fix listed |
| Medium | UBUNTU-CVE-2025-9230 | openssl | 1.1.1f-1ubuntu2.24+esm1 |
| Medium | GHSA-4xc9-xhrj-v574 | lodash | 4.17.11 |
| Medium | UBUNTU-CVE-2021-23965 | mozjs68 | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.1.0latest | 2 months ago | 11.7.0 | 66601,3162,933 | 64,489 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.