StackRadar

CVE-2018-21270

Medium

Advisory

Published 20 Jun 2019In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.037
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
31
of 17,781 indexed, latest versions
Container images
30
deployed by those charts
Fix available
1 of 1
affected package

Out-of-bounds Read in stringstream

Carried by container images the latest versions of 31 of 17,781 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
stringstreamnpm0.0.4, 0.0.50.0.630
OSV records
GHSA-mf6x-7mm4-x2g7

Charts affected

31 by stars
ChartLatestAffected imagesRadar Score
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
stringstream@0.0.5
0.0.6

Open the chart page →

7,210
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
stringstream@0.0.5
0.0.6

Open the chart page →

10,732
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
stringstream@0.0.5
0.0.6

Open the chart page →

5,209
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
stringstream@0.0.5
0.0.6
hyperledger/fabric-couchdb:0.4.15f6c724592abf
stringstream@0.0.5
0.0.6

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
stringstream@0.0.5
0.0.6
hyperledger/fabric-couchdb:0.4.15f6c724592abf
stringstream@0.0.5
0.0.6

Open the chart page →

77,687
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
koumoul/openapi-viewer:18eeca2e8285b
stringstream@0.0.5
0.0.6

Open the chart page →

38,346
splice-helmsplice-helm0.1.71 of 13See more

splice-helm splice-helm 0.1.7

1 of the 13 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
stringstream@0.0.5
0.0.6

Open the chart page →

1,477
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
stringstream@0.0.5
0.0.6
hyperledger/fabric-couchdb:0.4.15f6c724592abf
stringstream@0.0.5
0.0.6

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
stringstream@0.0.5
0.0.6
hyperledger/fabric-couchdb:0.4.15f6c724592abf
stringstream@0.0.5
0.0.6

Open the chart page →

77,706
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
stringstream@0.0.5
0.0.6

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
stringstream@0.0.5
0.0.6

Open the chart page →

4,069
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
stringstream@0.0.4
0.0.6

Open the chart page →

12,779
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
stringstream@0.0.5
0.0.6

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
stringstream@0.0.5
0.0.6

Open the chart page →

27,417
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
stringstream@0.0.5
0.0.6

Open the chart page →

33,963
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
stringstream@0.0.5
0.0.6

Open the chart page →

77,758
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
stringstream@0.0.5
0.0.6

Open the chart page →

70,895
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
stringstream@0.0.5
0.0.6

Open the chart page →

5,209
logentriesfairwinds-incubator0.2.21 of 1See more

logentries fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
logentries/docker-logentries:0.2.1f1f90a236998
stringstream@0.0.5
0.0.6

Open the chart page →

1,597
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
stringstream@0.0.5
0.0.6

Open the chart page →

5,941
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
stringstream@0.0.5
0.0.6
ibmcom/app-nav-ui:1.0.1e2a86997b36b
stringstream@0.0.5
0.0.6

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
stringstream@0.0.5
0.0.6
ibmcom/microclimate-portal:latested5505e5c7ec
stringstream@0.0.5
0.0.6
ibmcom/microclimate-theia:lateste17bdccc5030
stringstream@0.0.5
0.0.6

Open the chart page →

57,669
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
stringstream@0.0.5
0.0.6

Open the chart page →

4,614
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
stringstream@0.0.5
0.0.6

Open the chart page →

5,786
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
stringstream@0.0.5
0.0.6
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
stringstream@0.0.5
0.0.6

Open the chart page →

7,048
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
stringstream@0.0.5
0.0.6

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
stringstream@0.0.5
0.0.6

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
stringstream@0.0.5
0.0.6

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
stringstream@0.0.5
0.0.6

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
stringstream@0.0.4
0.0.6

Open the chart page →

36,215
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2018-21270.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
stringstream@0.0.5
0.0.6

Open the chart page →

3,638

Container images carrying it

30 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
stringstream@0.0.5
0.0.6
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
stringstream@0.0.5
0.0.6
4
pantsel/konga:latestc8172b75607d
stringstream@0.0.5
0.0.6
3
migmartri/prerender:latest486aacfd5aa9
stringstream@0.0.5
0.0.6
2
daskdev/dask-notebook:1.1.0052630f5ca04
stringstream@0.0.5
0.0.6
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
stringstream@0.0.5
0.0.6
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
stringstream@0.0.5
0.0.6
1
galaxy/galaxy-init:v18.010267bad550e6
stringstream@0.0.5
0.0.6
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
stringstream@0.0.5
0.0.6
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
stringstream@0.0.5
0.0.6
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
stringstream@0.0.5
0.0.6
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
stringstream@0.0.5
0.0.6
1
ibmcom/microclimate-portal:latested5505e5c7ec
stringstream@0.0.5
0.0.6
1
ibmcom/microclimate-theia:lateste17bdccc5030
stringstream@0.0.5
0.0.6
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
stringstream@0.0.5
0.0.6
1
konradkleine/docker-registry-frontend:v2181aad54ee64
stringstream@0.0.5
0.0.6
1
koumoul/openapi-viewer:18eeca2e8285b
stringstream@0.0.5
0.0.6
1
linuxserver/cloud9:latest45c5fe102ff3
stringstream@0.0.5
0.0.6
1
logentries/docker-logentries:0.2.1f1f90a236998
stringstream@0.0.5
0.0.6
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
stringstream@0.0.5
0.0.6
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
stringstream@0.0.5
0.0.6
1
muluder/prograncontrollermcord:0.1.843b597a93da7
stringstream@0.0.5
0.0.6
1
omecproject/onos-progran:1.0.05715e5648aa0
stringstream@0.0.5
0.0.6
1
openthread/otbr:latestf307f59f6432
stringstream@0.0.4
0.0.6
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
stringstream@0.0.4
0.0.6
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
stringstream@0.0.5
0.0.6
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
stringstream@0.0.5
0.0.6
1
wekanteam/wekan:v4.2268a51f0327df
stringstream@0.0.5
0.0.6
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
stringstream@0.0.5
0.0.6
1
quay.io/wekan/wekan:v5.65cb17600883a3
stringstream@0.0.5
0.0.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.