StackRadar

CVE-2018-7408

High

Advisory

Published 13 May 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
28
deployed by those charts
Fix available
1 of 1
affected package

Incorrect Permission Assignment for Critical Resource in NPM

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 28 images.

Affected packageAffected versionsFixed inImages
npmnpm1.0.1, 1.39.1-prel, 3.5.2, 3.10.3+5 more5.7.128
OSV records
GHSA-ph34-pc88-72gc

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
npm@1.0.1
5.7.1

Open the chart page →

4,577
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
npm@3.10.10
5.7.1

Open the chart page →

10,732
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
npm@1.0.1
5.7.1

Open the chart page →

8,212
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
npm@5.6.0
5.7.1
hyperledger/fabric-couchdb:0.4.15f6c724592abf
npm@5.6.0
5.7.1

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
npm@5.6.0
5.7.1
hyperledger/fabric-couchdb:0.4.15f6c724592abf
npm@5.6.0
5.7.1

Open the chart page →

77,687
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
koumoul/openapi-viewer:18eeca2e8285b
npm@5.5.1
5.7.1

Open the chart page →

38,346
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
npm@1.0.1
5.7.1

Open the chart page →

31,844
splice-helmsplice-helm0.1.71 of 13See more

splice-helm splice-helm 0.1.7

1 of the 13 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
npm@3.10.10
5.7.1

Open the chart page →

1,477
dltkvassist-iot-data-integrity-verification0.2.02 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
npm@5.6.0
5.7.1
hyperledger/fabric-couchdb:0.4.15f6c724592abf
npm@5.6.0
5.7.1

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.02 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

2 of the 9 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
npm@5.6.0
5.7.1
hyperledger/fabric-couchdb:0.4.15f6c724592abf
npm@5.6.0
5.7.1

Open the chart page →

77,706
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
npm@3.5.2
5.7.1

Open the chart page →

12,779
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
npm@5.6.0
5.7.1

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@5.6.0
5.7.1

Open the chart page →

27,417
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
npm@5.6.0
5.7.1

Open the chart page →

33,963
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
npm@4.2.0
5.7.1

Open the chart page →

77,758
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
npm@5.6.0
5.7.1

Open the chart page →

70,895
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
npm@1.0.1
5.7.1

Open the chart page →

14,559
logentriesfairwinds-incubator0.2.21 of 1See more

logentries fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
logentries/docker-logentries:0.2.1f1f90a236998
npm@3.10.9
5.7.1

Open the chart page →

1,597
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
5.7.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
5.7.1

Open the chart page →

24,319
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
npm@5.6.0
5.7.1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
npm@5.6.0
5.7.1

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
npm@5.6.0
5.7.1
ibmcom/microclimate-portal:latested5505e5c7ec
npm@5.6.0
5.7.1
ibmcom/microclimate-theia:lateste17bdccc5030
npm@5.6.0
5.7.1

Open the chart page →

57,669
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
npm@4.2.0
5.7.1

Open the chart page →

4,614
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
npm@3.10.10
5.7.1

Open the chart page →

5,786
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
npm@4.2.0
5.7.1

Open the chart page →

7,048
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
npm@3.10.3
5.7.1

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
npm@5.6.0
5.7.1

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
npm@5.6.0
5.7.1

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2018-7408.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2
5.7.1

Open the chart page →

36,215

Container images carrying it

28 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
npm@5.6.0
5.7.1
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
npm@5.6.0
5.7.1
4
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
5.7.1
2
migmartri/prerender:latest486aacfd5aa9
npm@4.2.0
5.7.1
2
codercom/code-server:4.11.0-debian1e2cc688008e
npm@1.0.1
5.7.1
1
codercom/code-server:3.10.247605610ad8d
npm@1.0.1
5.7.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
npm@5.6.0
5.7.1
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@5.6.0
5.7.1
1
galaxy/galaxy-init:v18.010267bad550e6
npm@5.6.0
5.7.1
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
npm@5.6.0
5.7.1
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
npm@5.6.0
5.7.1
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
npm@5.6.0
5.7.1
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
npm@5.6.0
5.7.1
1
ibmcom/microclimate-portal:latested5505e5c7ec
npm@5.6.0
5.7.1
1
ibmcom/microclimate-theia:lateste17bdccc5030
npm@5.6.0
5.7.1
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
npm@3.10.10
5.7.1
1
koumoul/openapi-viewer:18eeca2e8285b
npm@5.5.1
5.7.1
1
linuxserver/cloud9:latest45c5fe102ff3
npm@3.10.3
5.7.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
npm@1.0.1
5.7.1
1
logentries/docker-logentries:0.2.1f1f90a236998
npm@3.10.9
5.7.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
npm@3.10.10
5.7.1
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
npm@3.10.10
5.7.1
1
muluder/prograncontrollermcord:0.1.843b597a93da7
npm@5.6.0
5.7.1
1
omecproject/onos-progran:1.0.05715e5648aa0
npm@5.6.0
5.7.1
1
openthread/otbr:latestf307f59f6432
npm@3.5.2
5.7.1
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2
5.7.1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
npm@4.2.0
5.7.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
npm@1.0.1
5.7.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.