clowder2 Helm chart
ncsaVerified publisherScored 14 Sept 2026
Open Source Data Management for Long Tail Data. Clowder is a customizable and scalable data management framework to support any data format and multiple research domains.
Latest 1.9.7 9 months agoapp version 2.0.0-beta.4 1Artifact Hub
clowder2 1.9.7 deploys 12 container images: bitnamilegacy/minio, bitnamilegacy/mongodb, clowder/clowder2-backend, clowder/clowder2-frontend and 8 more. Across them, 3,298 findings — 14 critical, 33 high — 12 on CISA KEV. The highest contribution is GHSA-f58c-gq56-vjjf in tika-core 2.7.0, fixed in 3.2.2.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnamilegacy/ | 2023.12.23 | 0226180 | 2,291 |
| bitnamilegacy/ | 5.0.10 | 1631206 | 2,886 |
| clowder/ | 2.0.0-beta.4 | 0246243 | 3,250 |
| clowder/ | 2.0.0-beta.4 | 012074 | 1,091 |
| clowder/ | 2.0.0-beta.4 | 0246243 | 3,250 |
| clowder/ | 2.0.0-beta.4 | 0246243 | 3,250 |
| bitnamilegacy/ | 12-debian-12-r16 | 3662308 | 4,456 |
| bitnamilegacy/ | 8.12.2 | 7695538 | 7,598 |
| bitnamilegacy/ | 15.5.0 | 2025125 | 1,897 |
| library/ | 1.28 | 0000 | 0 |
| bitnamilegacy/ | 20.0.5 | 1357454 | 5,465 |
| bitnamilegacy/ | 3.10.8 | 0315165 | 1,939 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | BIT-java-2026-21932 | Java | 1.8.0 |
| Low | BIT-java-2026-21932 | java | 1.8.0 |
| Low | DEBIAN-CVE-2025-24528 | krb5 | 1.20.1-2+deb12u3 |
| Low | GHSA-f2hx-5fx3-hmcv | keycloak-services | 26.5.7 |
| Low | GHSA-4fvr-rgm6-gqmc | aiohttp | 3.14.1 |
| Low | DEBIAN-CVE-2026-66034 | libssh2 | 1.10.0-3+deb12u1 |
| Low | GHSA-m6q9-p373-g5q8 | keycloak-services | 22.0.10 |
| Low | GO-2021-0317 | stdlib | 1.16.14 |
| Low | GHSA-hj3v-m684-v259 | github.com/ | 1.2.29 |
| Low | DEBIAN-CVE-2025-7458 | sqlite3 | no fix listed |
| Low | GHSA-mvh2-crg5-v77c | netty-codec-http | 4.1.136.Final |
| Low | DEBIAN-CVE-2025-15661 | libssh2 | 1.10.0-3+deb12u1 |
| Low | BIT-postgresql-2026-14668 | postgresql | 14.24.0 |
| Low | BIT-postgresql-2026-14668 | PostgreSQL | 14.24.0 |
| Low | BIT-java-2024-20921 | Java | 1.8.0 |
| Low | BIT-java-2024-20921 | java | 1.8.0 |
| Low | GHSA-mrv8-pqfj-7gp5 | keycloak-services | 22.0.10 |
| Low | GHSA-m297-3jv9-m927 | keycloak-services | 26.5.5 |
| Low | GO-2023-2185 | stdlib | 1.20.11 |
| Low | DEBIAN-CVE-2026-54411 | pam | no fix listed |
| Low | DEBIAN-CVE-2026-2219 | dpkg | 1.21.23 |
| Low | DEBIAN-CVE-2026-42497 | perl | no fix listed |
| Low | GHSA-c9v3-4pv7-87pr | github.com/ | 1.14.2 |
| Low | GHSA-h383-gmxw-35v2 | log4j-1.2-api | 2.25.4 |
| Low | DEBIAN-CVE-2026-41992 | gzip | no fix listed |
| Low | BIT-minio-2026-39414 | MinIO | 2026.04.10 |
| Low | BIT-minio-2026-39414 | minio | 2026.04.10 |
| Low | GHSA-h749-fxx7-pwpg | github.com/ | no fix listed |
| Low | GHSA-558v-64gr-wgg4 | netty-codec | 4.1.136.Final |
| Low | GHSA-c3fc-8qff-9hwx | bcprov-jdk18on | 1.84 |
| Low | GHSA-w354-2f3c-qvg9 | keycloak-services | no fix listed |
| Low | GHSA-hj93-h7pg-fh6v | keycloak-services | 26.5.7 |
| Low | GHSA-cjm2-j6cm-6p6m | keycloak-services | 26.5.7 |
| Low | GHSA-mm3m-5497-xggg | elasticsearch | 8.16.0 |
| Low | GHSA-jgx4-7v3v-vwfm | elasticsearch | 8.13.3 |
| Low | DSA-5504-1 | bind9 | 1:9.16.44-1~deb11u1 |
| Low | GHSA-46c8-635v-68r2 | keycloak-services | 22.0.10 |
| Low | DEBIAN-CVE-2024-4603 | openssl | 3.0.14-1~deb12u1 |
| Low | DEBIAN-CVE-2026-12064 | curl | no fix listed |
| Low | DLA-3878-1 | libxml2 | 2.9.10+dfsg-6.7+deb11u5 |
| Low | GHSA-9ph3-v2vh-3qx7 | vertx-core | 4.4.8 |
| Low | GHSA-82w8-qh3p-5jfq | starlette | 1.3.1 |
| Low | DEBIAN-CVE-2026-8932 | curl | no fix listed |
| Low | DEBIAN-CVE-2024-12133 | libtasn1-6 | 4.19.0-2+deb12u1 |
| Low | GHSA-xwmg-2g98-w7v9 | nimbus-jose-jwt | 9.37.4 |
| Low | DEBIAN-CVE-2026-8286 | curl | no fix listed |
| Low | BIT-java-2024-20919 | Java | 1.8.0 |
| Low | BIT-java-2024-20919 | java | 1.8.0 |
| Low | GHSA-wf93-45jw-7689 | pip | 26.1.2 |
| Low | GHSA-8xfc-gm6g-vgpv | bc-fips | 1.0.2.5 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.9.7latest | 9 months ago | 2.0.0-beta.4 | 14334692,779 | 37,373 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.