StackRadar

CVE-2019-16769

Medium

Advisory

Published 5 Dec 2019In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.2
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Cross-Site Scripting in serialize-javascript

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
serialize-javascriptnpm1.6.1, 1.7.0, 1.9.12.1.110
OSV records
GHSA-h9rv-jmmf-4pgx

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
serialize-javascript@1.7.0
2.1.1

Open the chart page →

6,868
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
serialize-javascript@1.9.1
2.1.1

Open the chart page →

3,237
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
serialize-javascript@1.6.1
2.1.1

Open the chart page →

29,901
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
serialize-javascript@1.7.0
2.1.1

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
serialize-javascript@1.9.1
2.1.1

Open the chart page →

12,907
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
serialize-javascript@1.7.0
2.1.1

Open the chart page →

32,915
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
serialize-javascript@1.9.1
2.1.1

Open the chart page →

6,454
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
serialize-javascript@1.7.0
2.1.1

Open the chart page →

7,929
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
serialize-javascript@1.9.1
2.1.1

Open the chart page →

6,524
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2019-16769.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
serialize-javascript@1.9.1
2.1.1

Open the chart page →

3,881

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
serialize-javascript@1.7.0
2.1.1
1
conduction/conduction-ui-app:devd591f5e6f2a9
serialize-javascript@1.9.1
2.1.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
serialize-javascript@1.6.1
2.1.1
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
serialize-javascript@1.7.0
2.1.1
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
serialize-javascript@1.9.1
2.1.1
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
serialize-javascript@1.7.0
2.1.1
1
jayfong/yapi:1.10.2163e5d621910
serialize-javascript@1.9.1
2.1.1
1
phntom/codimd:2.4.31b9aafbb62e6
serialize-javascript@1.9.1
2.1.1
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
serialize-javascript@1.9.1
2.1.1
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
serialize-javascript@1.7.0
2.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.