StackRadar

CVE-2019-12402

High

Advisory

Published 11 Oct 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.162
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

Denial of Service in Apache Commons Compress

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
commons-compressmaven1.16.1, 1.17, 1.181.1918
OSV records
GHSA-53x6-4x5p-rrvv

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
commons-compress@1.18
1.19
dbanda/spark:2.4.6d0e6367876ae
commons-compress@1.18
1.19

Open the chart page →

13,738
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
commons-compress@1.18
1.19

Open the chart page →

6,165
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
commons-compress@1.18
1.19
seldonio/cluster-manager:0.2.729e362bb1ba2
commons-compress@1.18
1.19

Open the chart page →

13,798
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-compress@1.16.1
1.19

Open the chart page →

2,837
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
commons-compress@1.18
1.19

Open the chart page →

26,944
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
commons-compress@1.18
1.19
ibmcom/app-nav-was-controller:1.0.1a6748792da26
commons-compress@1.18
1.19

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
commons-compress@1.18
1.19

Open the chart page →

39,349
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
thehiveproject/cortex:3.1.7f4bc64fb8844
commons-compress@1.18
1.19

Open the chart page →

6,122
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
commons-compress@1.18
1.19

Open the chart page →

26,356
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
commons-compress@1.17
1.19

Open the chart page →

43,341
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
commons-compress@1.18
1.19

Open the chart page →

8,098
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
commons-compress@1.18
1.19

Open the chart page →

13,767
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-compress@1.18
1.19

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-compress@1.18
1.19

Open the chart page →

3,176
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2019-12402.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
commons-compress@1.18
1.19

Open the chart page →

5,460

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dbanda/livy:0.80ca125e68e53
commons-compress@1.18
1.19
1
dbanda/spark:2.4.6d0e6367876ae
commons-compress@1.18
1.19
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
commons-compress@1.18
1.19
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
commons-compress@1.18
1.19
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
commons-compress@1.18
1.19
1
ladeit/ladeit:latest962b665ffe82
commons-compress@1.18
1.19
1
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-compress@1.16.1
1.19
1
library/sonarqube:8.2-communitya246bc64207e
commons-compress@1.18
1.19
1
library/storm:2.4.0bd5d420506d6
commons-compress@1.18
1.19
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
commons-compress@1.17
1.19
1
seldonio/apife:0.2.7ba81b17f00eb
commons-compress@1.18
1.19
1
seldonio/apife:0.3.1eea0d3f578ca
commons-compress@1.18
1.19
1
seldonio/cluster-manager:0.2.729e362bb1ba2
commons-compress@1.18
1.19
1
sismics/docs:v1.10f4b0ef019cf1
commons-compress@1.18
1.19
1
thehiveproject/cortex:3.1.7f4bc64fb8844
commons-compress@1.18
1.19
1
trinodb/trino:405ee80ab5eeab2
commons-compress@1.18
1.19
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-compress@1.18
1.19
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-compress@1.18
1.19
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.