StackRadar

bpjstk-service 1.0.0 Helm chart

openshift

Scored 14 Sept 2026

BPJSTK Multichannel Payment Gateway

Version 1.0.0deploys tag latest 0Artifact Hub

bpjstk-service 1.0.0 deploys 6 container images: andrianrf/bpjstk-simulator, andrianrf/iso-server, andrianrf/iso-client, andrianrf/bpjstk-service and 2 more. Across them, 1,730 findings55 critical, 130 high 38 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-boot-starter-web 2.3.4.RELEASE, fixed in 2.5.12. Chart.yaml declares kubeVersion >=1.20.0; rendered for Kubernetes 1.20.0.

Radar Score

34,67155130646899

1,730 findings over 6 of 6 images measured

KEV ×38 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
andrianrf/bpjstk-simulatorlatest61254933,239
andrianrf/iso-serverlatest17201481857,310
andrianrf/iso-clientlatest815731054,066
andrianrf/bpjstk-servicelatest81463983,767
andrianrf/backoffice-belatest13181361946,645
andrianrf/backofficelatest3511722249,644

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Critical findings

21 distinct across the version’s images

Critical: findings whose contribution to the Radar Score is 70–100. Show every band

SeverityAdvisoryPackageFixed in
CriticalGHSA-36p3-wjmg-h94xKEVspring-beans@5.2.9.RELEASE5.2.20.RELEASE
CriticalGHSA-36p3-wjmg-h94xKEVspring-boot-starter-web@2.3.4.RELEASE2.5.12
CriticalGHSA-36p3-wjmg-h94xKEVspring-webmvc@5.2.9.RELEASE5.2.20.RELEASE
CriticalGHSA-83qj-6fr2-vhqgKEVtomcat-embed-core@9.0.389.0.99
CriticalGHSA-45hx-wfhj-473xh2@1.4.2002.1.210
CriticalRHSA-2024:3339glibc@2.34-60.el90:2.34-100.el9_4.2
CriticalRHSA-2024:3411glibc@2.34-60.el90:2.34-60.el9_2.14
CriticalGHSA-h376-j262-vhq6h2@1.4.2002.0.206
CriticalGHSA-mjmj-j48q-9wg2snakeyaml@1.262.0
CriticalRHSA-2025:3384KEVfreetype@2.10.4-9.el90:2.10.4-10.el9_2
CriticalRHSA-2023:5453KEVglibc@2.34-60.el90:2.34-60.el9_2.7
CriticalRHSA-2026:1473openssl@1:3.0.7-6.el9_21:3.5.1-7.el9_7
CriticalRHSA-2026:1594openssl@1:3.0.7-6.el9_21:3.0.7-18.el9_2.3
CriticalRHSA-2023:5713KEVnginx@1:1.20.1-1.module+el8.8.0+20359+9bd89172.11:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1
CriticalRHSA-2023:5838KEVnghttp2@1.43.0-5.el90:1.43.0-5.el9_2.1
CriticalRHSA-2023:5763curl@7.76.1-23.el9_2.10:7.76.1-23.el9_2.4
CriticalRHSA-2023:6745curl@7.76.1-23.el9_2.10:7.76.1-26.el9_3.2
CriticalGHSA-5j33-cvvr-w245tomcat-embed-core@9.0.389.0.98
CriticalGHSA-m7jv-hq7h-mq7ctomcat-embed-websocket@9.0.369.0.37
CriticalRHSA-2026:18041nginx@1:1.20.1-1.module+el8.8.0+20359+9bd89172.11:1.24.0-3.module+el8.10.0+24290+dc7f88b5.1
CriticalRHSA-2025:11992sqlite@3.34.1-6.el9_10:3.34.1-8.el9_6

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latestlatest5513064689934,671

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/openshift/bpjstk-service.svg)](https://charts.stackradar.io/charts/openshift/bpjstk-service)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.