StackRadar

CVE-2017-18640

High

Advisory

Published 4 Jun 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.267
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
137
of 17,781 indexed, latest versions
Container images
126
deployed by those charts
Fix available
1 of 1
affected package

SnakeYAML Entity Expansion during load operation

Carried by container images the latest versions of 137 of 17,781 indexed charts deploy, on 126 images.

Affected packageAffected versionsFixed inImages
snakeyamlmaven1.11, 1.12, 1.13, 1.15+9 more1.26126
OSV records
GHSA-rvwf-54qp-4r6v

Charts affected

137 by stars
ChartLatestAffected imagesRadar Score
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
snakeyaml@1.15
1.26

Open the chart page →

14,066
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
snakeyaml@1.19
1.26

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.11 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

1 of the 8 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
solsson/kafka-prometheus-jmx-exporterdigest-pinned6f82e2b0464f
snakeyaml@1.16
1.26

Open the chart page →

58,857
dadosfake-helmdadosfake-app0.1.01 of 1See more

dadosfake-helm dadosfake-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
snakeyaml@1.20
1.26

Open the chart page →

2,064
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
snakeyaml@1.17
1.26

Open the chart page →

8,245
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
snakeyaml@1.15
1.26

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
snakeyaml@1.23
1.26

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
snakeyaml@1.23
1.26

Open the chart page →

4,592
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
snakeyaml@1.19
1.26

Open the chart page →

11,782
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
snakeyaml@1.11
1.26

Open the chart page →

20,205
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
snakeyaml@1.15
1.26

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
snakeyaml@1.24
1.26

Open the chart page →

19,802
shenyuerdeng2.4.212 of 2See more

shenyu erdeng 2.4.21

2 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
snakeyaml@1.25
1.26
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
snakeyaml@1.25
1.26

Open the chart page →

12,513
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
snakeyaml@1.23
1.26

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
snakeyaml@1.23
1.26

Open the chart page →

55,600
my-chartfleet-web-app0.1.03 of 6See more

my-chart fleet-web-app 0.1.0

3 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
snakeyaml@1.17
1.26
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
snakeyaml@1.17
1.26
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
snakeyaml@1.17
1.26

Open the chart page →

24,296
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
snakeyaml@1.15
1.26

Open the chart page →

2,113
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
snakeyaml@1.19
1.26

Open the chart page →

6,988
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
snakeyaml@1.25
1.26

Open the chart page →

19,215
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
snakeyaml@1.17
1.26

Open the chart page →

27,949
jaegergpg-dev3.3.31 of 5See more

jaeger gpg-dev 3.3.3

1 of the 5 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/cassandra:3.11.65aa8400b4b3b
snakeyaml@1.11
1.26

Open the chart page →

19,229
hdfsgradiant-bigdataVerified publisher0.1.101 of 2See more

hdfs gradiant-bigdata 0.1.10

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26

Open the chart page →

7,073
hivegradiant-bigdataVerified publisher0.1.61 of 5See more

hive gradiant-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26

Open the chart page →

20,837
opentsdbgradiant-bigdataVerified publisher0.1.73 of 6See more

opentsdb gradiant-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
snakeyaml@1.18
1.26
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26
spdigital/prometheus-jmx-exporter-kubernetes:0.3.1e916950138ee
snakeyaml@1.16
1.26

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
snakeyaml@1.15
1.26

Open the chart page →

6,147
supertokensgraphql-hive1.0.01 of 1See more

supertokens graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
supertokens/supertokens-postgresql:3.1418d34c781347
snakeyaml@1.24
1.26

Open the chart page →

2,709
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
spdigital/prometheus-jmx-exporter-kubernetes:0.3.1e916950138ee
snakeyaml@1.16
1.26
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
snakeyaml@1.18
1.26

Open the chart page →

10,540
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
snakeyaml@1.23
1.26

Open the chart page →

3,978
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
snakeyaml@1.19
1.26

Open the chart page →

6,451
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
snakeyaml@1.19
1.26
ibmcom/app-nav-was-controller:1.0.1a6748792da26
snakeyaml@1.19
1.26

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
snakeyaml@1.17
1.26
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
snakeyaml@1.15
1.26

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
snakeyaml@1.18
1.26

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
snakeyaml@1.17
1.26
ibmcom/microclimate-theia:lateste17bdccc5030
snakeyaml@1.17
1.26

Open the chart page →

57,669
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
snakeyaml@1.15
1.26

Open the chart page →

6,174
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
snakeyaml@1.16
1.26

Open the chart page →

10,777
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
snakeyaml@1.23
1.26

Open the chart page →

7,498
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
snakeyaml@1.23
1.26

Open the chart page →

4,153
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
snakeyaml@1.23
1.26

Open the chart page →

26,356
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
snakeyaml@1.17
1.26

Open the chart page →

7,929
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
snakeyaml@1.19
1.26

Open the chart page →

15,855
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
bitnamilegacy/jmx-exporter:0.16.1d81bfc40888f
snakeyaml@1.23
1.26

Open the chart page →

16,198
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
snakeyaml@1.15
1.26

Open the chart page →

4,911
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
snakeyaml@1.12
1.26

Open the chart page →

55,726
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
snakeyaml@1.24
1.26

Open the chart page →

3,633
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
snakeyaml@1.18
1.26

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
snakeyaml@1.17
1.26

Open the chart page →

88,546
omec-control-planeopencord0.1.312 of 8See more

omec-control-plane opencord 0.1.31

2 of the 8 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/cassandra:2.1.20cb079c0d7a57
snakeyaml@1.11
1.26
omecproject/c3po-hssdb:master-latest28a90cc26716
snakeyaml@1.11
1.26

Open the chart page →

40,715
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
snakeyaml@1.25
1.26

Open the chart page →

12,927
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
snakeyaml@1.17
1.26

Open the chart page →

38,865
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
snakeyaml@1.19
1.26

Open the chart page →

6,350

Container images carrying it

126 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fonoster/routr-edgeport:2.13.6d08a8a574a50
snakeyaml@1.18
1.26
1
fonoster/routr-requester:2.13.6e0c823506eb2
snakeyaml@1.18
1.26
1
gocd/gocd-server:v19.3.02da45cb09d57
snakeyaml@1.18
1.26
1
gradiant/hdfs:3.2.2e3bf364fe713
snakeyaml@1.16
1.26
1
gradiant/jmxproxy:3.4.045eceb1bc55c
snakeyaml@1.18
1.26
1
graylog2/server:2.4.3-38ff28c66e6c1
snakeyaml@1.17
1.26
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
snakeyaml@1.19
1.26
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
snakeyaml@1.19
1.26
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
snakeyaml@1.17
1.26
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
snakeyaml@1.15
1.26
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
snakeyaml@1.18
1.26
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
snakeyaml@1.17
1.26
1
ibmcom/microclimate-theia:lateste17bdccc5030
snakeyaml@1.17
1.26
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
snakeyaml@1.20
1.26
1
just1not2/streama:1.10.48a2305192dec
snakeyaml@1.17
1.26
1
keyfactor/signserver-ce:7.3.2798fbbe00283
snakeyaml@1.19
1.26
1
kimb88/hello-world-spring-boot:latest0639155241cb
snakeyaml@1.19
1.26
1
ladeit/ladeit:latest962b665ffe82
snakeyaml@1.23
1.26
1
library/cassandra:3.11.598531a31f213
snakeyaml@1.11
1.26
1
library/cassandra:3.11.10b095ff3248c6
snakeyaml@1.11
1.26
1
library/cassandra:2.1.20cb079c0d7a57
snakeyaml@1.11
1.26
1
library/elasticsearch:2.4.641ed3a1a16b6
snakeyaml@1.15
1.26
1
library/logstash:7.17.817a4f64e9cf5
snakeyaml@1.18
1.26
1
library/sonarqube:6.7.6-community0ae5169e3d0f
snakeyaml@1.15
1.26
1
library/sonarqube:8.2-communitya246bc64207e
snakeyaml@1.17
1.26
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
snakeyaml@1.25
1.26
1
lightbend/spark-history-server:2.4.00bedf37f428a
snakeyaml@1.15
1.26
1
marcelmay/hadoop-hdfs-fsimage-exporter:1.3abeccb740ef7
snakeyaml@1.25
1.26
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
snakeyaml@1.23
1.26
1
metabase/metabase:v0.31.2ffb2dccacefc
snakeyaml@1.18
1.26
1
microcks/microcks:0.8.0e3a3e0c67b09
snakeyaml@1.16
1.26
1
muluder/prograncontrollermcord:0.1.843b597a93da7
snakeyaml@1.17
1.26
1
nacos/nacos-server:1.4.1fe6e5688cdf3
snakeyaml@1.23
1.26
1
omecproject/c3po-hssdb:master-latest28a90cc26716
snakeyaml@1.11
1.26
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
snakeyaml@1.18
1.26
1
omecproject/onos-progran:1.0.05715e5648aa0
snakeyaml@1.17
1.26
1
onosproject/onos:2.2.144914a8d4b3f
snakeyaml@1.25
1.26
1
opencord/ves-agent:1.0.04187e2a8c918
snakeyaml@1.19
1.26
1
openkm/openkm-ce:6.3.113bc465a7461b
snakeyaml@1.17
1.26
1
openwhisk/invoker:1.0.0f5831ec85525
snakeyaml@1.23
1.26
1
openzipkin/zipkin:2.21.060c3970df479
snakeyaml@1.25
1.26
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
snakeyaml@1.25
1.26
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
snakeyaml@1.16
1.26
1
opsmx11/issuegen:v2.1.05c50ca123d88
snakeyaml@1.23
1.26
1
owasp/dependency-track:3.8.0efc65e702ee1
snakeyaml@1.24
1.26
1
paulczar/spring-helloworld:latestc7140cecd5f7
snakeyaml@1.23
1.26
1
prom/cloudwatch-exporter:cloudwatch_exporter-0.5.0923705b2ae77
snakeyaml@1.17
1.26
1
prom/cloudwatch-exporter:cloudwatch_exporter-0.8.0fc4b9b9f5e15
snakeyaml@1.17
1.26
1
reportportal/service-api:5.7.29df41f8fb320
snakeyaml@1.25
1.26
1
reportportal/service-authorization:5.7.09e73114dbd15
snakeyaml@1.25
1.26
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.