mojaloop/role-assignment-service:v2.1.0 container image
Docker HubScanned 14 Sept 2026
Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of mojaloop/role-assignment-service
mojaloop/role-assignment-service:v2.1.0 resolved to def4bf273721, scanned 14 Sept 2026: 180 findings, 0 critical; deployed by 2 charts, among them finance-portal and role-assignment-service.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
180 distinct on this digest
Findings for digest def4bf273721 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-phwq-j96m-2c2q | ejs | 3.1.7 |
| High | ALPINE-CVE-2024-6119 | openssl | 3.1.7-r0 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| High | ALPINE-CVE-2024-2511 | openssl | 3.1.4-r6 |
| Medium | GHSA-2p57-rm9w-gvfp | ip | no fix listed |
| Medium | ALPINE-CVE-2024-5535 | openssl | 3.1.6-r0 |
| Medium | GHSA-2w6w-674q-4c4q | handlebars | 4.7.9 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 3.0.4 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | ALPINE-CVE-2024-4741 | openssl | 3.1.6-r0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 1.13.5 |
| Medium | GHSA-wf6x-7x77-mvgw | immutable | 4.3.8 |
| Medium | GHSA-xq3m-2v4x-88gg | protobufjs | 7.5.5 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.1.8-r1 |
| Medium | GHSA-rf6f-7fwh-wjgh | flatted | 3.4.2 |
| Medium | GHSA-grv7-fg5c-xmjg | braces | 3.0.3 |
| Medium | GHSA-cgfm-xwp7-2cvr | sanitize-html | 2.7.1 |
| Medium | GHSA-pjwm-pj3p-43mv | axios | 0.32.0 |
| Medium | GHSA-jr5f-v2jv-69x6 | axios | 1.8.2 |
| Medium | GHSA-8hc4-vh64-cxmj | axios | 1.7.4 |
| Medium | GHSA-4hjh-wcwx-xvwj | axios | 1.12.0 |
| Medium | GHSA-282f-qqgm-c34q | jsonpointer | 5.0.0 |
| Medium | ALPINE-CVE-2024-9143 | openssl | 3.1.7-r1 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-xvcm-6775-5m9r | immutable | 4.3.9 |
| Medium | GHSA-5f97-h2c2-826q | @apidevtools/ | 11.2.0 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.1.8-r1 |
| Medium | GHSA-v88g-cgmw-v5xw | ajv | 6.12.3 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | GHSA-9wv6-86v2-598j | path-to-regexp | 0.1.10 |
| Medium | GHSA-3mfm-83xf-c92r | handlebars | 4.7.9 |
| Medium | GHSA-xhpv-hc6g-r9c6 | handlebars | 4.7.9 |
| Medium | GHSA-99f4-grh7-6pcq | @grpc/ | 1.9.16 |
| Medium | GHSA-3xgq-45jj-v275 | cross-spawn | 6.0.6 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | GHSA-qwcr-r2fm-qrc7 | body-parser | 1.20.3 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | GHSA-25h7-pfq9-p65f | flatted | 3.4.0 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 1.15.1 |
| Low | GHSA-vcc3-ghjq-m6fr | decode-uri-component | 0.5.0 |
| Low | GHSA-rhx6-c78j-4q9w | path-to-regexp | 0.1.12 |
| Low | GHSA-6vfc-qv3f-vr6c | markdown-it | 12.3.2 |
| Low | GHSA-62hf-57xw-28j9 | axios | 1.15.1 |
| Low | GHSA-34x7-hfp2-rc4v | tar | 7.5.7 |
| Low | GHSA-rjqq-98f6-6j3r | sanitize-html | 2.3.1 |
| Low | GHSA-q8qp-cvcw-x6jj | axios | 1.15.2 |
| Low | GHSA-3g43-6gmg-66jw | axios | 1.15.2 |
| Low | GHSA-cxjh-pqwp-8mfp | follow-redirects | 1.15.6 |
Used by
2 charts
| Chart | Version | Tag | Containers |
|---|---|---|---|
| finance-portalmojaloop | 5.1.4 | v2.1.0 | 1 |
| role-assignment-servicemojaloop | 3.1.0 | v2.1.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.