StackRadar

CVE-2019-14866

High

Advisory

Published 2 Nov 2019In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: cpio security update

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
cpiodeb2.11+dfsg-1ubuntu1, 2.11+dfsg-1ubuntu1.1, 2.11+dfsg-1ubuntu1.22.11+dfsg-1ubuntu1.2+esm17
cpiorpm2.11-27.el7, 2.12-lp151.2.680:2.11-28.el7, 2.12-lp151.3.3.112
OSV records
UBUNTU-CVE-2019-14866RHSA-2020:3908openSUSE-SU-2019:2596-1
Also known as
USN-4176-1

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
rke2-canalrke2-charts3.13.31 of 2See more

rke2-canal rke2-charts 3.13.3

1 of the 2 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
cpio@2.11-27.el7
0:2.11-28.el7

Open the chart page →

6,996
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
cpio@2.11+dfsg-1ubuntu1
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

41,427
opensipschetan-opensips0.1.01 of 1See more

opensips chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
chetangautamm/repo:Opensips_Buildb4b94155ff5a
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

30,140
guestbookcloudnativeapp0.2.01 of 3See more

guestbook cloudnativeapp 0.2.0

1 of the 3 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
resouer/redis-slave:v2e2f198b49ba7
cpio@2.11+dfsg-1ubuntu1.1
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

36,839
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1
galaxy/galaxy-stable:v18.018e577a626dfd
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

70,895
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
cpio@2.11-27.el7
0:2.11-28.el7
ibmcom/app-nav-ui:1.0.1e2a86997b36b
cpio@2.11-27.el7
0:2.11-28.el7

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.06 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

6 of the 6 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
cpio@2.11-27.el7
0:2.11-28.el7
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cpio@2.11-27.el7
0:2.11-28.el7
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
cpio@2.11-27.el7
0:2.11-28.el7
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
cpio@2.11-27.el7
0:2.11-28.el7
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
cpio@2.11-27.el7
0:2.11-28.el7
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
cpio@2.11-27.el7
0:2.11-28.el7

Open the chart page →

39,349
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
cpio@2.11-27.el7
0:2.11-28.el7

Open the chart page →

4,505
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
cpio@2.11+dfsg-1ubuntu1
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

41,427
sebaopencord1.0.01 of 17See more

seba opencord 1.0.0

1 of the 17 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
voltha/voltha-envoy:1.6.059ab2a00f712
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

93,855
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1

Open the chart page →

26,339
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2019-14866.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
cpio@2.12-lp151.2.68
2.12-lp151.3.3.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
cpio@2.12-lp151.2.68
2.12-lp151.3.3.1

Open the chart page →

11,942

Container images carrying it

19 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
wurstmeister/zookeeper:latest7a7fd44a7210
cpio@2.11+dfsg-1ubuntu1
2.11+dfsg-1ubuntu1.2+esm1
2
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
cpio@2.12-lp151.2.68
2.12-lp151.3.3.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
cpio@2.12-lp151.2.68
2.12-lp151.3.3.1
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1
1
galaxy/galaxy-init:v18.010267bad550e6
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1
1
galaxy/galaxy-stable:v18.018e577a626dfd
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
cpio@2.11-27.el7
0:2.11-28.el7
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
cpio@2.11-27.el7
0:2.11-28.el7
1
opsmx11/issuegen:v2.1.05c50ca123d88
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1
1
rancher/hardened-calico:v3.13.36d2cd61a338b
cpio@2.11-27.el7
0:2.11-28.el7
1
resouer/redis-slave:v2e2f198b49ba7
cpio@2.11+dfsg-1ubuntu1.1
2.11+dfsg-1ubuntu1.2+esm1
1
voltha/voltha-envoy:1.6.059ab2a00f712
cpio@2.11+dfsg-1ubuntu1.2
2.11+dfsg-1ubuntu1.2+esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.