CVE-2014-9356
MediumAdvisory
Published 18 May 2021In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.049
- 92nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Path Traversal in Docker
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0 | 1.3.3 | 6 |
- OSV records
- GHSA-vj3f-3286-r4pf
- Also known as
- GO-2022-0751
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| openelbkubesphere-stable | 0.5.0 | 1 of 2See more | 4,329 |
| atlantistrozz | 3.12.11 | 1 of 1See more | 5,280 |
| argocddevtron | 1.8.1 | 1 of 3See more | 10,466 |
| argocddevtron-labs | 1.8.1 | 1 of 3See more | 10,466 |
| openelbkubesphere-testVerified publisher | 0.2.4 | 1 of 2See more | 4,329 |
| porterkubesphere-testVerified publisher | 0.2.2 | 1 of 2See more | 2,784 |
| kube-oidc-proxymesosphere | 0.3.4 | 1 of 1See more | 3,144 |
| argocdromholdings | 1.8.1 | 1 of 3See more | 10,466 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| argoproj/ | 830e86cacefd | github.com/ | 1.3.3 | 3 |
| kubesphere/ | b5b665c4672c | github.com/ | 1.3.3 | 1 |
| kubesphere/ | ed7311a0f9e4 | github.com/ | 1.3.3 | 1 |
| kubesphere/ | 8d1ed5ee1d2e | github.com/ | 1.3.3 | 1 |
| runatlantis/ | 45fbaf7e207c | github.com/ | 1.3.3 | 1 |
| quay.io/ | e045b26eb6df | github.com/ | 1.3.3 | 1 |