StackRadar

CVE-2018-1000654

Medium

Advisory

Published 20 Aug 2018In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
319
of 17,781 indexed, latest versions
Container images
216
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 319 of 17,781 indexed charts deploy, on 216 images.

Affected packageAffected versionsFixed inImages
libtasn1-6deb3.4-3ubuntu0.1, 3.4-3ubuntu0.5, 3.4-3ubuntu0.6, 4.7-3ubuntu0.16.04.2+2 more4.7-3ubuntu0.16.04.3+esm2170
libtasn1apk4.12-r2, 4.13-r04.12-r4, 4.14-r046
OSV records
ALPINE-CVE-2018-1000654UBUNTU-CVE-2018-1000654
Also known as
USN-5352-1

Charts affected

319 by stars
ChartLatestAffected imagesRadar Score
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
libtasn1-6@4.13-2
no fix listed

Open the chart page →

10,568
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
libtasn1-6@4.13-2
no fix listed

Open the chart page →

10,514
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
shenyutest-helm2.4.212 of 2See more

shenyu test-helm 2.4.21

2 of the 2 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
libtasn1@4.13-r0
4.14-r0
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
libtasn1@4.13-r0
4.14-r0

Open the chart page →

12,513
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
libtasn1-6@4.7-3ubuntu0.16.04.2
4.7-3ubuntu0.16.04.3+esm2

Open the chart page →

11,007
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
libtasn1-6@4.13-2
no fix listed

Open the chart page →

6,793
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libtasn1-6@4.7-3ubuntu0.16.04.3
4.7-3ubuntu0.16.04.3+esm2

Open the chart page →

15,330
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
libtasn1-6@4.13-2
no fix listed

Open the chart page →

7,885
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
libtasn1-6@4.13-2
no fix listed

Open the chart page →

20,190
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
libtasn1@4.13-r0
4.14-r0

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
libtasn1@4.13-r0
4.14-r0

Open the chart page →

3,176
wbaas-backupwbstack0.1.01 of 1See more

wbaas-backup wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
libtasn1-6@4.13-2
no fix listed

Open the chart page →

9,743
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
libtasn1-6@4.13-2
no fix listed

Open the chart page →

10,843
clickhousezloi-space1.2.01 of 3See more

clickhouse zloi-space 1.2.0

1 of the 3 container images this version deploys carry CVE-2018-1000654.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
libtasn1-6@4.13-2
no fix listed

Open the chart page →

9,207

Container images carrying it

216 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
libtasn1@4.13-r0
4.14-r0
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
libtasn1-6@4.13-2
no fix listed
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
libtasn1-6@4.13-2
no fix listed
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libtasn1-6@4.13-2
no fix listed
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
libtasn1-6@4.13-2
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
libtasn1-6@4.13-2
no fix listed
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
libtasn1@4.12-r2
4.12-r4
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
libtasn1@4.13-r0
4.14-r0
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
libtasn1@4.13-r0
4.14-r0
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
libtasn1-6@4.13-2
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
libtasn1-6@4.13-2
no fix listed
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
libtasn1-6@4.13-2
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
libtasn1-6@4.13-2
no fix listed
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
libtasn1-6@4.13-2
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
libtasn1-6@4.7-3ubuntu0.16.04.3
4.7-3ubuntu0.16.04.3+esm2
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libtasn1-6@4.7-3ubuntu0.16.04.3
4.7-3ubuntu0.16.04.3+esm2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.