clowder2 Helm chart
ncsaVerified publisherScored 14 Sept 2026
Open Source Data Management for Long Tail Data. Clowder is a customizable and scalable data management framework to support any data format and multiple research domains.
Latest 1.9.7 9 months agoapp version 2.0.0-beta.4 1Artifact Hub
clowder2 1.9.7 deploys 12 container images: bitnamilegacy/minio, bitnamilegacy/mongodb, clowder/clowder2-backend, clowder/clowder2-frontend and 8 more. Across them, 3,298 findings — 14 critical, 33 high — 12 on CISA KEV. The highest contribution is GHSA-f58c-gq56-vjjf in tika-core 2.7.0, fixed in 3.2.2.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnamilegacy/ | 2023.12.23 | 0226180 | 2,291 |
| bitnamilegacy/ | 5.0.10 | 1631206 | 2,886 |
| clowder/ | 2.0.0-beta.4 | 0246243 | 3,250 |
| clowder/ | 2.0.0-beta.4 | 012074 | 1,091 |
| clowder/ | 2.0.0-beta.4 | 0246243 | 3,250 |
| clowder/ | 2.0.0-beta.4 | 0246243 | 3,250 |
| bitnamilegacy/ | 12-debian-12-r16 | 3662308 | 4,456 |
| bitnamilegacy/ | 8.12.2 | 7695538 | 7,598 |
| bitnamilegacy/ | 15.5.0 | 2025125 | 1,897 |
| library/ | 1.28 | 0000 | 0 |
| bitnamilegacy/ | 20.0.5 | 1357454 | 5,465 |
| bitnamilegacy/ | 3.10.8 | 0315165 | 1,939 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | ALPINE-CVE-2026-6732 | libxml2 | 2.13.9-r1 |
| Low | DEBIAN-CVE-2026-32316 | jq | 1.6-2.1+deb12u2 |
| Low | GHSA-45q3-82m4-75jr | netty-handler-proxy | 4.1.133.Final |
| Low | GHSA-h2qv-fj59-j46j | netty-codec-haproxy | 4.1.135.Final |
| Low | GHSA-qcq2-496w-v96p | mistune | 3.3.0 |
| Low | GHSA-rp95-xpg9-c2cq | keycloak-services | 26.6.2 |
| Low | DEBIAN-CVE-2026-0915 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2025-4802 | glibc | 2.36-9+deb12u11 |
| Low | DEBIAN-CVE-2023-50495 | ncurses | no fix listed |
| Low | GHSA-6jhg-hg63-jvvf | aiohttp | 3.13.3 |
| Low | BIT-elasticsearch-2024-52979 | Elasticsearch | 7.17.25 |
| Low | BIT-elasticsearch-2024-52979 | elasticsearch | 7.17.25 |
| Low | GHSA-g3cq-j2xw-wf74 | aiohttp | 3.14.1 |
| Low | GO-2022-0435 | stdlib | 1.17.9 |
| Low | GHSA-w3g8-r9gw-qrh8 | keycloak-quarkus-server | 26.0.8 |
| Low | BIT-elasticsearch-2024-43709 | Elasticsearch | 7.17.21 |
| Low | BIT-elasticsearch-2024-43709 | elasticsearch | 7.17.21 |
| Low | DEBIAN-CVE-2026-13608 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-5773 | curl | 7.88.1-10+deb12u15 |
| Low | GHSA-cc37-9q2j-3hfv | netty-codec-haproxy | 4.1.135.Final |
| Low | GHSA-g84x-mcqj-x9qq | aiohttp | 3.13.3 |
| Low | GHSA-3wrr-7qpf-2prh | jackson-databind | 2.14.0 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | DEBIAN-CVE-2026-63072 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-40355 | krb5 | 1.20.1-2+deb12u5 |
| Low | GHSA-w33c-445m-f8w7 | okio-jvm | 3.4.0 |
| Low | GHSA-cwq8-g58r-32hg | github.com/ | 0.0.0-20241213221912-68b004a48f41 |
| Low | GHSA-8wv5-x4w7-5gww | github.com/ | 0.24.0 |
| Low | GHSA-jj3x-wxrx-4x23 | aiohttp | 3.13.3 |
| Low | DEBIAN-CVE-2026-40356 | krb5 | 1.20.1-2+deb12u5 |
| Low | ALPINE-CVE-2026-45445 | openssl | 3.5.7-r0 |
| Low | DEBIAN-CVE-2026-45445 | openssl | 3.0.20-1~deb12u2 |
| Low | GO-2022-0288 | stdlib | 1.16.12 |
| Low | BIT-mongodb-2026-11933 | mongodb | 4.4.31 |
| Low | DEBIAN-CVE-2026-85091 | zlib | no fix listed |
| Low | BIT-postgresql-2026-6637 | postgresql | 14.23.0 |
| Low | BIT-postgresql-2026-6637 | PostgreSQL | 14.23.0 |
| Low | GHSA-574f-3g2m-x479 | bcprov-jdk18on | 1.80.2 |
| Low | BIT-mongodb-2025-3085 | mongodb | 5.0.31 |
| Low | DEBIAN-CVE-2024-33600 | glibc | 2.36-9+deb12u7 |
| Low | DLA-3907-1 | sqlite3 | 3.34.1-3+deb11u1 |
| Low | BIT-postgresql-2026-18408 | postgresql | 14.24.0 |
| Low | BIT-postgresql-2026-18408 | PostgreSQL | 14.24.0 |
| Low | GHSA-q2x7-8rv6-6q7h | jinja2 | 3.1.5 |
| Low | GHSA-hcvw-475w-8g7p | keycloak-services | 26.2.13 |
| Low | GHSA-488m-w9fp-5mm2 | protostream | 4.6.2.Final |
| Low | GO-2023-2102 | stdlib | 1.20.10 |
| Low | GHSA-3fhx-3vvg-2j84 | quarkus-core | 2.16.8.Final |
| Low | GHSA-hw58-3793-42gg | keycloak-services | 26.2.2 |
| Low | DSA-5439-1 | bind9 | 1:9.16.42-1~deb11u1 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.9.7latest | 9 months ago | 2.0.0-beta.4 | 14334692,779 | 37,373 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.