CVE-2019-18218
HighAdvisory
Published 21 Oct 2019In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.018
- 78th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 156
- of 17,781 indexed, latest versions
- Container images
- 131
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: file security update
Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 131 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| filedeb | 1:5.14-2ubuntu3.2, 1:5.14-2ubuntu3.3, 1:5.14-2ubuntu3.4, 1:5.22+15-2+deb8u3+10 more | 1:5.14-2ubuntu3.4+esm1, 1:5.22+15-2+deb8u6, 1:5.25-2ubuntu1.3, 1:5.30-1+deb9u3+2 more | 85 |
| filerpm | 5.32-lp151.7.22, 5.33-8.el8, 5.33-13.el8, 5.33-13.el8_2.1+2 more | 0:5.33-20.el8, 5.32-lp151.8.3.1 | 43 |
| fileapk | 5.32-r0, 5.35-r0 | 5.32-r2, 5.36-r1 | 3 |
- OSV records
- ALPINE-CVE-2019-18218RHSA-2021:4374UBUNTU-CVE-2019-18218DLA-1969-1DSA-4550-1openSUSE-SU-2020:0677-1
- Also known as
- USN-4172-1, USN-4172-2
Charts affected
156 by stars
Container images carrying it
131 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| svtechnmaa/ | e19aba397c1f | file | 1:5.35-4+deb10u1 | 1 |
| tenstartups/ | 379d9338c720 | file | 5.36-r1 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | file | 1:5.25-2ubuntu1.3 | 1 |
| timothyclarke/ | 40a80ced8031 | file | 1:5.22+15-2+deb8u6 | 1 |
| tpdock/ | 3da600c95a49 | file | 1:5.25-2ubuntu1.3 | 1 |
| voltha/ | c4e41e92f046 | file | 1:5.25-2ubuntu1.3 | 1 |
| voltha/ | 59ab2a00f712 | file | 1:5.14-2ubuntu3.4+esm1 | 1 |
| voltha/ | 37f80524c207 | file | 1:5.25-2ubuntu1.3 | 1 |
| voltha/ | 9ee8c1f4428c | file | 1:5.25-2ubuntu1.3 | 1 |
| voltha/ | 655c3048a602 | file | 1:5.25-2ubuntu1.3 | 1 |
| voltha/ | ff596b62de59 | file | 1:5.25-2ubuntu1.3 | 1 |
| woojoong/ | ec230db19652 | file | 1:5.32-2ubuntu0.3 | 1 |
| zenko/ | 386a1f48ec0e | file | 1:5.22+15-2+deb8u6 | 1 |
| ghcr.io/ | 0cf25ed621e2 | file | 0:5.33-20.el8 | 1 |
| ghcr.io/ | 0635f17c9d2c | file | 0:5.33-20.el8 | 1 |
| ghcr.io/ | e34964e336c1 | file | 0:5.33-20.el8 | 1 |
| ghcr.io/ | 0c5a3398d1e4 | file | 0:5.33-20.el8 | 1 |
| ghcr.io/ | 8ba040e79ca0 | file | 0:5.33-20.el8 | 1 |
| ghcr.io/ | 8caf5289fe73 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | cdefc81c6b2e | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 10df27bc5560 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | a3b9a07648b6 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | ea838e5b4051 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 7a4b9fedc724 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 3029dc0f1d38 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 107a7c73af59 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 6722d5041b47 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 0bbe8b451fa3 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 89ee6493af89 | file | 0:5.33-20.el8 | 1 |
| quay.io/ | 6ba82beff18e | file | 0:5.33-20.el8 | 1 |
| registry.gitlab.com/ | cf72810d33f5 | file | 0:5.33-20.el8 | 1 |