StackRadar

CVE-2019-17498

High

Advisory

Published 21 Oct 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
69
of 17,781 indexed, latest versions
Container images
66
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libssh2 security update

Carried by container images the latest versions of 69 of 17,781 indexed charts deploy, on 66 images.

Affected packageAffected versionsFixed inImages
libssh2deb1.4.3-4.1+deb8u1, 1.5.0-2ubuntu0.1, 1.8.0-2.1build11.4.3-4.1+deb8u6, 1.5.0-2ubuntu0.1+esm136
libssh2apk1.8.0-r4, 1.8.2-r01.9.0-r112
libssh2rpm1.4.3-12.el7_6.2, 1.4.3-12.el7_6.3, 1.8.0-3.el70:1.8.0-4.el718
OSV records
ALPINE-CVE-2019-17498UBUNTU-CVE-2019-17498RHSA-2020:3915DLA-1991-1
Also known as
USN-5308-1

Charts affected

69 by stars
ChartLatestAffected imagesRadar Score
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7

Open the chart page →

4,505
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libssh2@1.8.0-3.el7
0:1.8.0-4.el7

Open the chart page →

2,063
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

4,614
oauth2-proxyjenkins-x0.2.31 of 1See more

oauth2-proxy jenkins-x 0.2.3

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
a5huynh/oauth2_proxy:2.20c7307d31ca8
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

2,392
Wordressjinchi-chart0.2.01 of 2See more

Wordress jinchi-chart 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339
helm-controllerkubedex0.4.01 of 1See more

helm-controller kubedex 0.4.0

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
kubedex/helm-controller:v1.0.14f1008c51ef9
libssh2@1.4.3-12.el7_6.3
0:1.8.0-4.el7

Open the chart page →

2,422
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

7,048
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

55,726
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
libssh2@1.8.2-r0
1.9.0-r1

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
libssh2@1.8.2-r0
1.9.0-r1

Open the chart page →

26,211
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

29,124
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

2,939
Wordresssix0.2.01 of 2See more

Wordress six 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libssh2@1.8.0-2.1build1
no fix listed

Open the chart page →

30,687
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

3,116
Wordressuvaise-wordpress0.2.01 of 2See more

Wordress uvaise-wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339
Wordresswordpress0.2.01 of 2See more

Wordress wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-17498.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6

Open the chart page →

1,339

Container images carrying it

66 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
4
library/wordpress:4.8-apache6216f64ab88f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
4
library/consul:1.6.194cdbd83f24e
libssh2@1.8.2-r0
1.9.0-r1
3
mautic/mautic:2.13-apachea954c5868d76
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1
3
danisla/hadoop:2.9.0255ba2dd739b
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
2
migmartri/prerender:latest486aacfd5aa9
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
libssh2@1.8.2-r0
1.9.0-r1
2
a5huynh/oauth2_proxy:2.20c7307d31ca8
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
billimek/comcastusage-for-influxdb:latest801bba1228ac
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
buoyantio/linkerd:1.1.2f4048edaca6f
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
camptocamp/imap-mailbox-exporter:latest9dec019e4c62
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
camptocamp/ldap-search-exporter:latest5e55370dd292
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
camptocamp/r10k-dashboard:0.2.6073be594d145
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
codylundquist/helm-rethinkdb-cluster:0.1.0630ab586b8c1
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
datadog/operator:0.3.117f08a860090
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
gitlab/gitlab-runner:alpine-v12.3.0a83c15bda342
libssh2@1.8.2-r0
1.9.0-r1
1
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
libssh2@1.8.2-r0
1.9.0-r1
1
gocd/gocd-server:v19.3.02da45cb09d57
libssh2@1.8.2-r0
1.9.0-r1
1
graylog2/server:2.4.3-38ff28c66e6c1
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
hazelcast/hazelcast-jet:3.0df495e64ea65
libssh2@1.8.2-r0
1.9.0-r1
1
hickey/puppet_forge:1.10.0c1148a09ef20
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7
1
ibmcom/app-nav-controller:1.0.1ee4624ba513d
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/galera-mariadb:10.2.142dcde9774493
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
libssh2@1.8.2-r0
1.9.0-r1
1
ibmcom/icp-storage-util:3.2.0c44e1ef21075
libssh2@1.8.2-r0
1.9.0-r1
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libssh2@1.8.0-3.el7
0:1.8.0-4.el7
1
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
libssh2@1.8.0-r4
1.9.0-r1
1
kubedex/helm-controller:v1.0.14f1008c51ef9
libssh2@1.4.3-12.el7_6.3
0:1.8.0-4.el7
1
library/orientdb:3.0.1318a6c004398f
libssh2@1.8.0-r4
1.9.0-r1
1
library/percona:5.7.17d5d7f368de4a
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
neilpeterson/get-tweet:v28b645ac1a23e
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
libssh2@1.4.3-4.1+deb8u1
1.4.3-4.1+deb8u6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.