StackRadar

CVE-2018-25031

Medium

Advisory

Published 12 Mar 2022In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.423
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Spoofing attack in swagger-ui

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
swagger-uimaven2.1.0, 3.17.6, 3.23.11, 3.24.3+3 more4.1.310
OSV records
GHSA-cr3q-pqgq-m8c2

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
swagger-ui@2.1.0
4.1.3

Open the chart page →

8,866
clamapicnieg2.0.51 of 2See more

clamapi cnieg 2.0.5

1 of the 2 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
swagger-ui@3.49.0
4.1.3

Open the chart page →

4,671
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
swagger-ui@3.24.3
4.1.3

Open the chart page →

8,986
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
swagger-ui@3.49.0
4.1.3

Open the chart page →

12,581
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
swagger-ui@3.17.6
4.1.3

Open the chart page →

27,949
sharrygeek-cookbookVerified publisher5.4.21 of 1See more

sharry geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
eikek0/sharry:1.8.0661ff3ef42cd
swagger-ui@3.49.0
4.1.3

Open the chart page →

1,419
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
swagger-ui@3.23.11
4.1.3

Open the chart page →

10,777
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
swagger-ui@3.38.0
4.1.3

Open the chart page →

4,278
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
swagger-ui@3.23.11
4.1.3

Open the chart page →

13,767
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
swagger-ui@3.52.5
4.1.3

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2018-25031.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
swagger-ui@3.52.5
4.1.3

Open the chart page →

28,605

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hookiesolutions/webhookie:latest0629694246ba
swagger-ui@3.52.5
4.1.3
2
apachepinot/pinot:latest-jdk110018bb04ced7
swagger-ui@3.23.11
4.1.3
1
audig/clamapi:2.1.62c3fe34ee430
swagger-ui@3.49.0
4.1.3
1
dniel/api-posts:master45a667852f2a
swagger-ui@3.24.3
4.1.3
1
eikek0/sharry:1.8.0661ff3ef42cd
swagger-ui@3.49.0
4.1.3
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
swagger-ui@2.1.0
4.1.3
1
gotson/komga:0.99.49b15ea6bfc30
swagger-ui@3.49.0
4.1.3
1
openkm/openkm-ce:6.3.113bc465a7461b
swagger-ui@3.17.6
4.1.3
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
swagger-ui@3.38.0
4.1.3
1
trinodb/trino:405ee80ab5eeab2
swagger-ui@3.23.11
4.1.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.