StackRadar

CVE-2019-17498

High

Advisory

Published 21 Oct 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
69
of 17,781 indexed, latest versions
Container images
66
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libssh2 security update

Carried by container images the latest versions of 69 of 17,781 indexed charts deploy, on 66 images.

Affected packageAffected versionsFixed inImages
libssh2deb1.4.3-4.1+deb8u1, 1.5.0-2ubuntu0.1, 1.8.0-2.1build11.4.3-4.1+deb8u6, 1.5.0-2ubuntu0.1+esm136
libssh2apk1.8.0-r4, 1.8.2-r01.9.0-r112
libssh2rpm1.4.3-12.el7_6.2, 1.4.3-12.el7_6.3, 1.8.0-3.el70:1.8.0-4.el718
OSV records
ALPINE-CVE-2019-17498UBUNTU-CVE-2019-17498RHSA-2020:3915DLA-1991-1
Also known as
USN-5308-1

Charts affected

69 by stars
ChartLatestAffected imagesRadar Score
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7

Open the chart page →

4,505
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libssh2@1.8.0-3.el7
0:1.8.0-4.el7

Open the chart page →

2,063
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

4,614
oauth2-proxyjenkins-x0.2.31 of 1See more

oauth2-proxy jenkins-x 0.2.3

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
a5huynh/oauth2_proxy:2.20c7307d31ca8
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

2,392
Wordressjinchi-chart0.2.01 of 2See more

Wordress jinchi-chart 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339
helm-controllerkubedex0.4.01 of 1See more

helm-controller kubedex 0.4.0

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
kubedex/helm-controller:v1.0.14f1008c51ef9
libssh2@1.4.3-12.el7_6.3
0:1.8.0-4.el7

Open the chart page →

2,422
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

7,048
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

55,726
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
libssh2@1.8.2-r0
1.9.0-r1

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
libssh2@1.8.2-r0
1.9.0-r1

Open the chart page →

26,211
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

29,124
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

2,939
Wordresssix0.2.01 of 2See more

Wordress six 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libssh2@1.8.0-2.1build1
no fix listed

Open the chart page →

30,687
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

3,116
Wordressuvaise-wordpress0.2.01 of 2See more

Wordress uvaise-wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339
Wordresswordpress0.2.01 of 2See more

Wordress wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339

Container images carrying it

66 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
neilpeterson/osba-storage-demo:latest29d229ab446e
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
percona/percona-xtradb-cluster:5.7.19eaa3fcb7a5a2
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
rancher/hardened-calico:v3.13.36d2cd61a338b
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
runatlantis/atlantis:v0.7.168fa470d1416
libssh2@1.8.0-r4
1.9.0-r1
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libssh2@1.8.0-2.1build1
no fix listed
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
tenstartups/ser2sock:latest379d9338c720
libssh2@1.8.0-r4
1.9.0-r1
1
timothyclarke/wptserver:2018-03-0840a80ced8031
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libssh2@1.8.0-2.1build1
no fix listed
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.