StackRadar

opendistro-es 1.4.1 Helm chart

lsst-sqre

Scored 14 Sept 2026

Open Distro for Elasticsearch

Version 1.4.1 6 years agoapp version 1.4.0 0Artifact Hub

opendistro-es 1.4.1 deploys 3 container images: library/busybox, amazon/opendistro-for-elasticsearch and amazon/opendistro-for-elasticsearch-kibana. Across them, 378 findings4 critical, 34 high 3 on CISA KEV. The highest contribution is GHSA-jfh8-c2jp-5v3q in log4j-core 2.11.1, fixed in 2.12.2. Chart.yaml declares kubeVersion ^1.10.0-0; rendered for Kubernetes 1.10.0.

Radar Score

7,929434164176

378 findings over 3 of 3 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
library/busybox×51.27.200000
amazon/opendistro-for-elasticsearch×31.4.042493704,736
amazon/opendistro-for-elasticsearch-kibana1.4.0010711063,193

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

378 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-w8wr-v893-vjvptar@4.4.107.5.18
LowGHSA-wf66-mphr-4c4rkafka-clients@2.0.13.9.2
LowGHSA-h35f-9h28-mq5csetuptools@0.9.883.0.0
LowGHSA-49q7-c7j4-3p7melliptic@6.4.06.5.7
LowGHSA-rx8g-88g5-qh64min-document@2.19.02.19.1
LowGHSA-6hwh-rqwf-cxxrvega-util@1.7.11.13.1
LowGHSA-84h7-rjj3-6jx4netty-codec-http@4.1.38.Final4.1.129.Final
LowMAL-2025-4362input_control_vis@kibanano fix listed
LowGHSA-q7cg-457f-vx79joi@13.7.017.13.4
LowGHSA-p9pc-299p-vxgpyargs-parser@9.0.213.1.2
LowGHSA-gvwx-54wh-qm9jtar@4.4.107.5.17
LowGHSA-434g-2637-qmqrelliptic@6.4.06.5.6
LowGHSA-vjh7-7g9h-fjfhelliptic@6.4.06.6.1
LowGHSA-68m8-v89j-7j2pbc-fips@1.0.11.0.2.4
LowGHSA-mqm9-c95h-x2p6angular@1.7.8no fix listed
LowGHSA-378v-28hj-76wfbn.js@4.11.84.12.3
LowGHSA-977x-g7h5-7qgwelliptic@6.4.06.5.7
LowGHSA-38f8-5428-x5cvnetty-codec-http@4.1.38.Final4.1.133.Final
LowGHSA-xq3w-v528-46rvnetty-common@4.1.38.Final4.1.115.Final
LowGHSA-m9gf-397r-hwpgangular@1.7.8no fix listed
LowGHSA-8c42-7qj2-3j46netty-codec-http@4.1.38.Final4.1.137.Final
LowGHSA-r7wm-3cxj-wff9jackson-core@2.8.112.18.8
LowGHSA-389x-839f-4rhxnetty-common@4.1.38.Final4.1.118.Final
LowGHSA-2hjr-vmf3-xwvpelasticsearch@7.4.27.17.16
LowGHSA-4mp9-239f-g9hgnetty-codec-http@4.1.38.Final4.1.136.Final
LowGHSA-fc9h-whq2-v747elliptic@6.4.06.6.0
LowGHSA-mh29-5h37-fv8mjs-yaml@3.13.13.14.2
LowGHSA-m9gh-789g-q5pvelasticsearch@7.4.28.19.8
LowGHSA-h9rv-jmmf-4pgxserialize-javascript@1.7.02.1.1
LowGHSA-h67p-54hq-rp68js-yaml@3.13.13.15.0
LowGHSA-6v5v-wf23-fmfqmarkdown-it@8.4.214.2.0
LowGHSA-hgj6-7826-r7m5jackson-databind@2.8.11.32.18.8
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@1.1.81.1.16
LowGHSA-5c6j-r48x-rmvqserialize-javascript@1.7.07.0.3
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.8.11.32.18.9
LowGHSA-vmf3-w455-68vhtar@4.4.107.5.16
LowGHSA-x426-x7cc-3fpc@hapi/wreck@15.0.118.1.2
LowGHSA-qx2v-qp2m-jg93postcss@7.0.178.5.10
LowGHSA-56r7-h6mw-rcfvelasticsearch@7.4.28.18.8
LowGHSA-gcjf-9mgh-3p7gnetty-codec-http@4.1.38.Final4.1.136.Final
LowGHSA-v8h7-rr48-vmmvnetty-codec-http@4.1.38.Final4.1.133.Final
LowGHSA-f7q4-pwc6-w24pelliptic@6.4.06.5.7
LowGHSA-j58c-ww9w-pwp5angular@1.7.8no fix listed
LowGHSA-2mvq-xp48-4c77subtext@6.0.7no fix listed
LowGHSA-36jr-mh4h-2g58d3-color@1.2.33.1.0
LowGHSA-5854-jvxx-2cg9content@4.0.5no fix listed
LowGHSA-5p4m-2wfm-xmqjjs-yaml@3.13.13.15.1
LowGHSA-6chw-6frg-f759acorn@6.3.06.4.1
LowGHSA-7hx8-2rxv-66xvhapi@17.6.0no fix listed
LowGHSA-g64q-3vg8-8f93pez@4.0.2no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.4.1latest6 years ago1.4.04341641767,929

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/lsst-sqre/opendistro-es.svg)](https://charts.stackradar.io/charts/lsst-sqre/opendistro-es)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.