StackRadar

feedbacksystem 0.48.3 Helm chart

thm-mni-iiVerified publisher

Scored 10 Oct 2026

Intelligent, personalized feedback for students using artificial intelligence

Version 0.48.3 yesterdayapp version v2.0.9 2Artifact Hub

feedbacksystem 0.48.3 deploys 14 container images: bitnamilegacy/minio, ghcr.io/thm-mni-ii/fbs-collab, ghcr.io/thm-mni-ii/fbs-core, ghcr.io/thm-mni-ii/fbs-core-web and 10 more. Across them, 2,179 findings — 28 critical, 34 high — 11 on CISA KEV. The highest contribution is GHSA-83qj-6fr2-vhqg in tomcat-embed-core 9.0.75, fixed in 9.0.99.

Radar Score

28,95828344581,658

2,179 findings over 14 of 14 images measured

KEV ×11 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

14 images
ImageTagVulnerabilitiesRadar Score
bitnamilegacy/minio2023.12.23-debian-11-r232541572,870
ghcr.io/thm-mni-ii/fbs-collabv2.0.900228334
ghcr.io/thm-mni-ii/fbs-corev2.0.9310572163,908
ghcr.io/thm-mni-ii/fbs-core-webv2.0.900020141
ghcr.io/thm-mni-ii/fbs-identity-servicev2.0.900141461,486
ghcr.io/thm-mni-ii/fbs-qcm-backendv2.0.90025811,305
ghcr.io/thm-mni-ii/fbs-qcm-frontendv2.0.913451772,902
ghcr.io/thm-mni-ii/fbs-runnerv2.0.935792164,253
library/docker20.10.21-dind511941794,634
ghcr.io/thm-mni-ii/fbs-sql-playground-webv2.0.900020141
ghcr.io/thm-mni-ii/fbs-web-shellv2.0.900020141
bitnamilegacy/mongodb×36.0.10-debian-11-r873421813,313
bitnamilegacy/mysql×28.0.35-debian-11-r22015941,352
bitnamilegacy/postgresql×315.4.0-debian-11-r4540311232,178

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

1,071 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-xx6v-rp6x-q39caxios@1.7.81.15.1
LowGHSA-7jxh-36q5-gcqvgithub.com/containerd/containerd@v1.6.16-0.20230124210447-1709cfe273d91.7.35
LowUBUNTU-CVE-2026-8674glibc@2.43-2ubuntu2.4no fix listed
LowGHSA-6p4f-wcwh-5vvmspring-webmvc@5.3.27no fix listed
LowGHSA-6p4f-wcwh-5vvmspring-webflux@5.3.27no fix listed
LowGO-2026-5027golang.org/x/net@v0.8.00.55.0
LowGO-2026-5029golang.org/x/net@v0.8.00.55.0
LowGO-2026-5030golang.org/x/net@v0.8.00.55.0
LowUBUNTU-CVE-2026-35341rust-coreutils@0.10.0-1ubuntu2~26.04.1no fix listed
LowGHSA-445q-vr5w-6q77axios@1.7.81.15.1
LowGHSA-v8h7-rr48-vmmvnetty-codec-http@4.1.92.Final4.1.133.Final
LowUBUNTU-CVE-2026-16599wget@1.25.0-2ubuntu4.4no fix listed
LowGHSA-957g-f97v-vppcspring-webmvc@5.3.27no fix listed
LowGO-2026-4340stdlib@go1.20.111.24.12
LowUBUNTU-CVE-2026-13757p11-kit@0.26.2-2no fix listed
LowUBUNTU-CVE-2026-93658rust-coreutils@0.10.0-1ubuntu2~26.04.1no fix listed
LowGHSA-vvgp-rfg2-7rr6jackson-databind@2.14.22.18.9
LowDLA-3875-1gnutls28@3.7.1-5+deb11u33.7.1-5+deb11u6
LowGHSA-cjpg-rgq5-fr37spring-webflux@5.3.27no fix listed
LowGHSA-cjpg-rgq5-fr37spring-webmvc@5.3.27no fix listed
LowGHSA-w9m9-85wc-3x92postcss-selector-parser@7.1.17.1.3
LowGHSA-wwpq-f5c3-7hvxspring-boot@2.7.12no fix listed
LowGHSA-9cmq-m9j5-mvwwspring-expression@5.3.275.3.39
LowGHSA-q2hr-2g5m-vwhrbrace-expansion@1.1.111.1.21
LowGHSA-898c-q2cr-xwhgaxios@1.7.81.16.0
LowGHSA-27gv-rfvv-22mvgithub.com/rabbitmq/amqp091-go@v1.9.01.13.0
LowDLA-4492-1gnutls28@3.7.1-5+deb11u33.7.1-5+deb11u9
LowALPINE-CVE-2024-13176openssl@3.1.4-r13.1.8-r0
LowDLA-4176-1openssl@1.1.1w-0+deb11u11.1.1w-0+deb11u3
LowGHSA-5p4m-2wfm-xmqjjs-yaml@4.1.04.3.1
LowGHSA-m425-mq94-257ggoogle.golang.org/grpc@v1.53.01.56.3
LowGHSA-xpw8-rcwv-8f8pnetty-codec-http2@4.1.92.Final4.1.100.Final
LowGHSA-q3v6-hm2v-pw99spring-security-core@5.7.85.7.14
LowGHSA-jfc7-64v2-mr8c@sigstore/core@2.0.03.2.1
LowGHSA-7g45-4rm6-3mm3guava@31.1-jre32.0.0-android
LowGO-2026-6612golang.org/x/net@v0.59.00.60.0
LowGO-2026-6612stdlib@go1.26.81.26.9
LowUBUNTU-CVE-2026-35352rust-coreutils@0.10.0-1ubuntu2~26.04.1no fix listed
LowALPINE-CVE-2026-42768openssl@3.5.6-r03.5.7-r0
LowGO-2023-1682github.com/opencontainers/runc@v1.1.31.1.5
LowGHSA-25qh-j22f-pwp8logback-core@1.2.121.3.16
LowUBUNTU-CVE-2026-56391coreutils-from@9.5-1ubuntu2+0.0.0~ubuntu259.7-3ubuntu2.1
LowUBUNTU-CVE-2026-35350rust-coreutils@0.10.0-1ubuntu2~26.04.1no fix listed
LowDLA-3930-1libsepol@3.1-13.1-1+deb11u1
LowGO-2026-6603golang.org/x/net@v0.59.00.60.0
LowGO-2026-6603stdlib@go1.26.81.26.9
LowGO-2026-6611golang.org/x/net@v0.59.00.60.0
LowGO-2026-6611stdlib@go1.26.81.26.9
LowDLA-4319-1libxml2@2.9.10+dfsg-6.7+deb11u42.9.10+dfsg-6.7+deb11u9
LowGHSA-g2v6-rqmx-r4w6@vue/server-renderer@3.5.133.5.42

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.48.3latestyesterdayv2.0.928344581,65828,958
0.48.24 days agov2.0.728344601,65628,635
0.48.19 days agov2.0.628344671,65129,321
0.48.016 days agov2.0.125394751,66228,958
0.47.11 year agov1.27.131485311,74531,792

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/thm-mni-ii/feedbacksystem.svg)](https://charts.stackradar.io/charts/thm-mni-ii/feedbacksystem)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 10 Oct 2026 · scanned 10 Oct 2026 · advisories as of 10 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.