StackRadar

CVE-2018-12538

High

Advisory

Published 16 Oct 2018In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.027
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

Access and integrity issue within Eclipse Jetty

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
jetty-servermaven9.4.0.v20161208, 9.4.5.v20170502, 9.4.6.v20170531, 9.4.8.v20171121+1 more9.4.11.v201806057
OSV records
GHSA-mwcx-532g-8pq3

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
jetty-server@9.4.8.v20171121
9.4.11.v20180605

Open the chart page →

2,406
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-server@9.4.6.v20170531
9.4.11.v20180605

Open the chart page →

5,078
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
jetty-server@9.4.8.v20171121
9.4.11.v20180605

Open the chart page →

7,226
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-server@9.4.10.v20180503
9.4.11.v20180605

Open the chart page →

16,860
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-server@9.4.0.v20161208
9.4.11.v20180605

Open the chart page →

4,303
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
jetty-server@9.4.5.v20170502
9.4.11.v20180605

Open the chart page →

10,682
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-server@9.4.10.v20180503
9.4.11.v20180605

Open the chart page →

15,855
jmxproxypndaproject0.1.01 of 1See more

jmxproxy pndaproject 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
gradiant/jmxproxy:3.4.045eceb1bc55c
jetty-server@9.4.8.v20171121
9.4.11.v20180605

Open the chart page →

4,177
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2018-12538.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-server@9.4.0.v20161208
9.4.11.v20180605

Open the chart page →

4,303

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-server@9.4.10.v20180503
9.4.11.v20180605
2
linuxserver/ubooquity:2.1.2-ls369932d6759112
jetty-server@9.4.0.v20161208
9.4.11.v20180605
2
bivas/presto:0.19605545994f806
jetty-server@9.4.8.v20171121
9.4.11.v20180605
1
gradiant/jmxproxy:3.4.045eceb1bc55c
jetty-server@9.4.8.v20171121
9.4.11.v20180605
1
jenkinsci/jenkins:2.67a1f33f004659
jetty-server@9.4.5.v20170502
9.4.11.v20180605
1
keyfactor/signserver-ce:7.3.2798fbbe00283
jetty-server@9.4.8.v20171121
9.4.11.v20180605
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
jetty-server@9.4.6.v20170531
9.4.11.v20180605
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.