StackRadar

CVE-2018-1000873

Medium

Advisory

Published 21 Dec 2018In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.048
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

Moderate severity vulnerability that affects com.fasterxml.jackson.datatype:jackson-datatype-jsr353

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
jackson-datatype-jsr310maven2.5.4, 2.6.7, 2.8.1, 2.8.6+7 more2.9.815
OSV records
GHSA-h4x4-5qp2-wp46

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
cmak-operatorcmak-operatorVerified publisher2.2.21 of 3See more

cmak-operator cmak-operator 2.2.2

1 of the 3 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
jackson-datatype-jsr310@2.8.11
2.9.8

Open the chart page →

4,605
kafka-managerradar-baseVerified publisher2.3.11 of 1See more

kafka-manager radar-base 2.3.1

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
jackson-datatype-jsr310@2.5.4
2.9.8

Open the chart page →

4,000
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
jackson-datatype-jsr310@2.8.9
2.9.8

Open the chart page →

8,063
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
jackson-datatype-jsr310@2.8.8
2.9.8

Open the chart page →

9,808
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jackson-datatype-jsr310@2.8.11
2.9.8

Open the chart page →

5,078
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
jackson-datatype-jsr310@2.8.1
2.9.8

Open the chart page →

7,226
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jackson-datatype-jsr310@2.9.5
2.9.8

Open the chart page →

16,860
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
jackson-datatype-jsr310@2.9.4
2.9.8

Open the chart page →

6,988
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
jackson-datatype-jsr310@2.9.6
2.9.8

Open the chart page →

6,451
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
jackson-datatype-jsr310@2.9.7
2.9.8

Open the chart page →

26,356
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jackson-datatype-jsr310@2.9.5
2.9.8

Open the chart page →

15,855
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jackson-datatype-jsr310@2.8.6
2.9.8

Open the chart page →

55,726
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
jackson-datatype-jsr310@2.9.5
2.9.8

Open the chart page →

6,350
jmxproxypndaproject0.1.01 of 1See more

jmxproxy pndaproject 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
gradiant/jmxproxy:3.4.045eceb1bc55c
jackson-datatype-jsr310@2.9.4
2.9.8

Open the chart page →

4,177
cerebrostakaterVerified publisher0.5.11 of 2See more

cerebro stakater 0.5.1

1 of the 2 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
lmenezes/cerebro:0.8.13e860068e403
jackson-datatype-jsr310@2.8.11
2.9.8

Open the chart page →

2,956
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2018-1000873.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jackson-datatype-jsr310@2.6.7
2.9.8

Open the chart page →

4,649

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jackson-datatype-jsr310@2.9.5
2.9.8
2
bivas/presto:0.19605545994f806
jackson-datatype-jsr310@2.8.1
2.9.8
1
choerodon/event-store-service:0.8.03c94c97f6f69
jackson-datatype-jsr310@2.8.8
2.9.8
1
craigwillis/c2metadata-bd:latestae317d7e4724
jackson-datatype-jsr310@2.8.6
2.9.8
1
folioci/mod-marccat:latest1b57d690d568
jackson-datatype-jsr310@2.9.4
2.9.8
1
gradiant/jmxproxy:3.4.045eceb1bc55c
jackson-datatype-jsr310@2.9.4
2.9.8
1
graylog2/server:2.4.3-38ff28c66e6c1
jackson-datatype-jsr310@2.8.9
2.9.8
1
kimb88/hello-world-spring-boot:latest0639155241cb
jackson-datatype-jsr310@2.9.6
2.9.8
1
ladeit/ladeit:latest962b665ffe82
jackson-datatype-jsr310@2.9.7
2.9.8
1
lmenezes/cerebro:0.8.13e860068e403
jackson-datatype-jsr310@2.8.11
2.9.8
1
opencord/ves-agent:1.0.04187e2a8c918
jackson-datatype-jsr310@2.9.5
2.9.8
1
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
jackson-datatype-jsr310@2.5.4
2.9.8
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jackson-datatype-jsr310@2.8.11
2.9.8
1
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
jackson-datatype-jsr310@2.8.11
2.9.8
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jackson-datatype-jsr310@2.6.7
2.9.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.