CVE-2018-2952
LowAdvisory
Published 18 Jul 2018In the index since 8 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.7
- base score, highest
- EPSS
- 0.042
- 90th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 14
- of 17,781 indexed, latest versions
- Container images
- 11
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
openjdk-8 - security update
Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 11 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openjdk-8deb | 8u131-b11-2, 8u141-b15-1~deb9u1, 8u151-b12-0ubuntu0.16.04.2, 8u151-b12-1~deb9u1+1 more | 8u181-b13-0ubuntu0.16.04.1, 8u181-b13-1~deb9u1 | 10 |
| openjdk-7deb | 7u65-2.5.2-3~14.04 | 7u181-2.6.14-0ubuntu0.2 | 1 |
- OSV records
- UBUNTU-CVE-2018-2952DSA-4268-1
- Also known as
- USN-3734-1, USN-3735-1
Charts affected
14 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| dltbrokerassist-iot-distributed-broker | 0.2.0 | 1 of 9See more | 77,706 |
| dltloggingassist-iot-logging-auditing | 0.2.0 | 1 of 9See more | 77,687 |
| tensorflow-notebookcloudnativeapp | 0.1.2 | 1 of 1See more | 36,094 |
| kafka-devwikimedia | 0.2.0 | 1 of 1See more | 41,427 |
| dltkvassist-iot-data-integrity-verification | 0.2.0 | 1 of 9See more | 77,706 |
| dltflassist-iot-dlt-based-fl | 0.2.0 | 1 of 9See more | 77,706 |
| distributed-tensorflowcloudnativeapp | 0.1.1 | 1 of 1See more | 36,094 |
| hlf-couchdbcloudnativeapp | 1.0.6 | 1 of 1See more | 33,963 |
| prestocloudnativeapp | 0.1.1 | 1 of 1See more | 7,226 |
| riemanncloudnativeapp | 0.1.2 | 1 of 1See more | 6,497 |
| my-chartfleet-web-app | 0.1.0 | 2 of 6See more | 24,296 |
| jenkinsjenkins-x | 0.10.38 | 1 of 2See more | 10,682 |
| polyglotncsaVerified publisher | 0.1.1 | 1 of 18See more | 55,726 |
| zookeeper-helm-chartnotesprojectchart | 0.1.0 | 1 of 1See more | 41,427 |
Container images carrying it
11 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| hyperledger/ | 4ce6f43ded2e | openjdk-8 | 8u181-b13-0ubuntu0.16.04.1 | 4 |
| wurstmeister/ | 7a7fd44a7210 | openjdk-7 | 7u181-2.6.14-0ubuntu0.2 | 2 |
| bivas/ | 05545994f806 | openjdk-8 | 8u181-b13-1~deb9u1 | 1 |
| cheyang/ | 46cc34755493 | openjdk-8 | 8u181-b13-0ubuntu0.16.04.1 | 1 |
| hyperledger/ | c65891b6c237 | openjdk-8 | 8u181-b13-0ubuntu0.16.04.1 | 1 |
| jenkinsci/ | a1f33f004659 | openjdk-8 | 8u181-b13-1~deb9u1 | 1 |
| ncsapolyglot/ | c44b22eb58bb | openjdk-8 | 8u181-b13-1~deb9u1 | 1 |
| raykrueger/ | c8baf3de57bb | openjdk-8 | 8u181-b13-1~deb9u1 | 1 |
| richardchesterwood/ | 0b540a28f5a6 | openjdk-8 | 8u181-b13-1~deb9u1 | 1 |
| richardchesterwood/ | 36c43961214c | openjdk-8 | 8u181-b13-1~deb9u1 | 1 |
| tensorflow/ | 1e3172090703 | openjdk-8 | 8u181-b13-0ubuntu0.16.04.1 | 1 |