StackRadar

CVE-2017-18640

High

Advisory

Published 4 Jun 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.267
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
137
of 17,781 indexed, latest versions
Container images
126
deployed by those charts
Fix available
1 of 1
affected package

SnakeYAML Entity Expansion during load operation

Carried by container images the latest versions of 137 of 17,781 indexed charts deploy, on 126 images.

Affected packageAffected versionsFixed inImages
snakeyamlmaven1.11, 1.12, 1.13, 1.15+9 more1.26126
OSV records
GHSA-rvwf-54qp-4r6v

Charts affected

137 by stars
ChartLatestAffected imagesRadar Score
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
snakeyaml@1.15
1.26

Open the chart page →

14,066
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
snakeyaml@1.19
1.26

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.11 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

1 of the 8 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
solsson/kafka-prometheus-jmx-exporterdigest-pinned6f82e2b0464f
snakeyaml@1.16
1.26

Open the chart page →

58,857
dadosfake-helmdadosfake-app0.1.01 of 1See more

dadosfake-helm dadosfake-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
snakeyaml@1.20
1.26

Open the chart page →

2,064
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
snakeyaml@1.17
1.26

Open the chart page →

8,245
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
snakeyaml@1.15
1.26

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
snakeyaml@1.23
1.26

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
snakeyaml@1.23
1.26

Open the chart page →

4,592
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
snakeyaml@1.19
1.26

Open the chart page →

11,782
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
snakeyaml@1.11
1.26

Open the chart page →

20,205
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
snakeyaml@1.15
1.26

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
snakeyaml@1.24
1.26

Open the chart page →

19,802
shenyuerdeng2.4.212 of 2See more

shenyu erdeng 2.4.21

2 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
snakeyaml@1.25
1.26
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
snakeyaml@1.25
1.26

Open the chart page →

12,513
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
snakeyaml@1.23
1.26

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
snakeyaml@1.23
1.26

Open the chart page →

55,600
my-chartfleet-web-app0.1.03 of 6See more

my-chart fleet-web-app 0.1.0

3 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
snakeyaml@1.17
1.26
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
snakeyaml@1.17
1.26
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
snakeyaml@1.17
1.26

Open the chart page →

24,296
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
snakeyaml@1.15
1.26

Open the chart page →

2,113
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
snakeyaml@1.19
1.26

Open the chart page →

6,988
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
snakeyaml@1.25
1.26

Open the chart page →

19,215
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
snakeyaml@1.17
1.26

Open the chart page →

27,949
jaegergpg-dev3.3.31 of 5See more

jaeger gpg-dev 3.3.3

1 of the 5 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/cassandra:3.11.65aa8400b4b3b
snakeyaml@1.11
1.26

Open the chart page →

19,229
hdfsgradiant-bigdataVerified publisher0.1.101 of 2See more

hdfs gradiant-bigdata 0.1.10

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26

Open the chart page →

7,073
hivegradiant-bigdataVerified publisher0.1.61 of 5See more

hive gradiant-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26

Open the chart page →

20,837
opentsdbgradiant-bigdataVerified publisher0.1.73 of 6See more

opentsdb gradiant-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
snakeyaml@1.18
1.26
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26
spdigital/prometheus-jmx-exporter-kubernetes:0.3.1e916950138ee
snakeyaml@1.16
1.26

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
snakeyaml@1.15
1.26

Open the chart page →

6,147
supertokensgraphql-hive1.0.01 of 1See more

supertokens graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
supertokens/supertokens-postgresql:3.1418d34c781347
snakeyaml@1.24
1.26

Open the chart page →

2,709
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
spdigital/prometheus-jmx-exporter-kubernetes:0.3.1e916950138ee
snakeyaml@1.16
1.26
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
snakeyaml@1.18
1.26

Open the chart page →

10,540
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
snakeyaml@1.23
1.26

Open the chart page →

3,978
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
snakeyaml@1.19
1.26

Open the chart page →

6,451
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
snakeyaml@1.19
1.26
ibmcom/app-nav-was-controller:1.0.1a6748792da26
snakeyaml@1.19
1.26

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
snakeyaml@1.17
1.26
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
snakeyaml@1.15
1.26

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
snakeyaml@1.18
1.26

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
snakeyaml@1.17
1.26
ibmcom/microclimate-theia:lateste17bdccc5030
snakeyaml@1.17
1.26

Open the chart page →

57,669
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
snakeyaml@1.15
1.26

Open the chart page →

6,174
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
snakeyaml@1.16
1.26

Open the chart page →

10,777
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
snakeyaml@1.23
1.26

Open the chart page →

7,498
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
snakeyaml@1.23
1.26

Open the chart page →

4,153
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
snakeyaml@1.23
1.26

Open the chart page →

26,356
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
snakeyaml@1.17
1.26

Open the chart page →

7,929
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
snakeyaml@1.19
1.26

Open the chart page →

15,855
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
bitnamilegacy/jmx-exporter:0.16.1d81bfc40888f
snakeyaml@1.23
1.26

Open the chart page →

16,198
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
snakeyaml@1.15
1.26

Open the chart page →

4,911
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
snakeyaml@1.12
1.26

Open the chart page →

55,726
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
snakeyaml@1.24
1.26

Open the chart page →

3,633
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
snakeyaml@1.18
1.26

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
snakeyaml@1.17
1.26

Open the chart page →

88,546
omec-control-planeopencord0.1.312 of 8See more

omec-control-plane opencord 0.1.31

2 of the 8 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
library/cassandra:2.1.20cb079c0d7a57
snakeyaml@1.11
1.26
omecproject/c3po-hssdb:master-latest28a90cc26716
snakeyaml@1.11
1.26

Open the chart page →

40,715
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
snakeyaml@1.25
1.26

Open the chart page →

12,927
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
snakeyaml@1.17
1.26

Open the chart page →

38,865
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2017-18640.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
snakeyaml@1.19
1.26

Open the chart page →

6,350

Container images carrying it

126 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
1.26
8
library/cassandra:3.11.3ce85468c5bad
snakeyaml@1.11
1.26
7
spdigital/prometheus-jmx-exporter-kubernetes:0.3.1e916950138ee
snakeyaml@1.16
1.26
5
gradiant/hbase-base:2.0.1a1ee6de94c04
snakeyaml@1.18
1.26
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
snakeyaml@1.25
1.26
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
snakeyaml@1.25
1.26
3
selenium/hub:3.141.5902f251d48d5f
snakeyaml@1.19
1.26
3
supertokens/supertokens-postgresql:3.1418d34c781347
snakeyaml@1.24
1.26
3
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
snakeyaml@1.19
1.26
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
snakeyaml@1.17
1.26
2
gradiant/spark:2.4.4-python-alpine97657d56e927
snakeyaml@1.15
1.26
2
library/cassandra:3.11.65aa8400b4b3b
snakeyaml@1.11
1.26
2
nacos/nacos-server:v2.1.0dcf04549c6d7
snakeyaml@1.23
1.26
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
snakeyaml@1.23
1.26
2
solsson/kafka-prometheus-jmx-exporter6f82e2b0464f
snakeyaml@1.16
1.26
2
sscaling/jmx-prometheus-exporter:0.3.011d9ee1b1e4a
snakeyaml@1.16
1.26
2
sscaling/jmx-prometheus-exporter48e3bd31f132
snakeyaml@1.16
1.26
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
snakeyaml@1.17
1.26
1
apacheignite/ignite:2.7.0d7deab68b8fa
snakeyaml@1.11
1.26
1
apache/iotdb:0.11.28647309f95d1
snakeyaml@1.17
1.26
1
apache/iotdb:0.13.3-nodeafa47bf1692a
snakeyaml@1.17
1.26
1
apache/nifi-registry:0.8.0974efa2f21da
snakeyaml@1.20
1.26
1
apachepinot/pinot:latest-jdk110018bb04ced7
snakeyaml@1.16
1.26
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
snakeyaml@1.19
1.26
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
snakeyaml@1.18
1.26
1
apache/skywalking-ui:8.1.067d50e4deff4
snakeyaml@1.17
1.26
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
snakeyaml@1.16
1.26
1
assistiot/automated_configuration:latest23f195a7a26a
snakeyaml@1.23
1.26
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
snakeyaml@1.18
1.26
1
atlassian/confluence-server:7.10.03b9222ab32ef
snakeyaml@1.22
1.26
1
atlassian/jira-software:9.7.264a75aa4ec4e
snakeyaml@1.19
1.26
1
bitnamilegacy/jmx-exporter:0.16.1d81bfc40888f
snakeyaml@1.23
1.26
1
camptocamp/jmx-exporter:0.12.058b9306482da
snakeyaml@1.16
1.26
1
choerodon/event-store-service:0.8.03c94c97f6f69
snakeyaml@1.17
1.26
1
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
snakeyaml@1.17
1.26
1
confluentinc/cp-kafka:5.4.01bbda887bc53
snakeyaml@1.23
1.26
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
snakeyaml@1.18
1.26
1
craigwillis/c2metadata-bd:latestae317d7e4724
snakeyaml@1.12
1.26
1
datappeal/hive-metastore:lateste38c085a3567
snakeyaml@1.16
1.26
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
snakeyaml@1.25
1.26
1
dbanda/livy:0.80ca125e68e53
snakeyaml@1.15
1.26
1
dbanda/spark:2.4.6d0e6367876ae
snakeyaml@1.16
1.26
1
deltaio/delta-sharing-server:0.2.08b75118187c5
snakeyaml@1.15
1.26
1
dniel/api-posts:master45a667852f2a
snakeyaml@1.23
1.26
1
dniel/forwardauth:latestf67129ea1c64
snakeyaml@1.23
1.26
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
snakeyaml@1.17
1.26
1
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
snakeyaml@1.25
1.26
1
folioci/mod-codex-ekb:latest235a3fa4adc9
snakeyaml@1.15
1.26
1
folioci/mod-marccat:latest1b57d690d568
snakeyaml@1.19
1.26
1
fonoster/routr:1.0.0-rc52ca65af17cbc
snakeyaml@1.18
1.26
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.