StackRadar

CVE-2019-18218

High

Advisory

Published 21 Oct 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.018
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
156
of 17,781 indexed, latest versions
Container images
131
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: file security update

Carried by container images the latest versions of 156 of 17,781 indexed charts deploy, on 131 images.

Affected packageAffected versionsFixed inImages
filedeb1:5.14-2ubuntu3.2, 1:5.14-2ubuntu3.3, 1:5.14-2ubuntu3.4, 1:5.22+15-2+deb8u3+10 more1:5.14-2ubuntu3.4+esm1, 1:5.22+15-2+deb8u6, 1:5.25-2ubuntu1.3, 1:5.30-1+deb9u3+2 more85
filerpm5.32-lp151.7.22, 5.33-8.el8, 5.33-13.el8, 5.33-13.el8_2.1+2 more0:5.33-20.el8, 5.32-lp151.8.3.143
fileapk5.32-r0, 5.35-r05.32-r2, 5.36-r13
OSV records
ALPINE-CVE-2019-18218RHSA-2021:4374UBUNTU-CVE-2019-18218DLA-1969-1DSA-4550-1openSUSE-SU-2020:0677-1
Also known as
USN-4172-1, USN-4172-2

Charts affected

156 by stars
ChartLatestAffected imagesRadar Score
Wordressuvaise-wordpress0.2.01 of 2See more

Wordress uvaise-wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-18218.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
file@1:5.22+15-2+deb8u3
1:5.22+15-2+deb8u6

Open the chart page →

1,339
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2019-18218.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
file@5.33-16.el8_3.1
0:5.33-20.el8

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2019-18218.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
file@1:5.30-1+deb9u2
1:5.30-1+deb9u3

Open the chart page →

10,127
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2019-18218.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
file@5.33-16.el8
0:5.33-20.el8

Open the chart page →

6,915
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2019-18218.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
file@1:5.30-1+deb9u2
1:5.30-1+deb9u3

Open the chart page →

22,665
Wordresswordpress0.2.01 of 2See more

Wordress wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-18218.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
file@1:5.22+15-2+deb8u3
1:5.22+15-2+deb8u6

Open the chart page →

1,339

Container images carrying it

131 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
svtechnmaa/svtech_http_thruk:v1.0.2e19aba397c1f
file@1:5.35-4
1:5.35-4+deb10u1
1
tenstartups/ser2sock:latest379d9338c720
file@5.35-r0
5.36-r1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
file@1:5.25-2ubuntu1
1:5.25-2ubuntu1.3
1
timothyclarke/wptserver:2018-03-0840a80ced8031
file@1:5.22+15-2+deb8u3
1:5.22+15-2+deb8u6
1
tpdock/freeradius:2.2.93da600c95a49
file@1:5.25-2ubuntu1
1:5.25-2ubuntu1.3
1
voltha/voltha-cli:1.6.0c4e41e92f046
file@1:5.25-2ubuntu1.1
1:5.25-2ubuntu1.3
1
voltha/voltha-envoy:1.6.059ab2a00f712
file@1:5.14-2ubuntu3.3
1:5.14-2ubuntu3.4+esm1
1
voltha/voltha-netconf:1.6.037f80524c207
file@1:5.25-2ubuntu1.1
1:5.25-2ubuntu1.3
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
file@1:5.25-2ubuntu1.1
1:5.25-2ubuntu1.3
1
voltha/voltha-tester:1.7.0655c3048a602
file@1:5.25-2ubuntu1.2
1:5.25-2ubuntu1.3
1
voltha/voltha-voltha:1.6.0ff596b62de59
file@1:5.25-2ubuntu1.1
1:5.25-2ubuntu1.3
1
woojoong/wowza:latestec230db19652
file@1:5.32-2ubuntu0.1
1:5.32-2ubuntu0.3
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
file@1:5.22+15-2+deb8u3
1:5.22+15-2+deb8u6
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
file@5.33-16.el8_3.1
0:5.33-20.el8
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
file@5.33-16.el8_3.1
0:5.33-20.el8
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
file@5.33-16.el8_3.1
0:5.33-20.el8
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
file@5.33-16.el8_3.1
0:5.33-20.el8
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
file@5.33-16.el8_3.1
0:5.33-20.el8
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
file@5.33-13.el8
0:5.33-20.el8
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
file@5.33-16.el8_3.1
0:5.33-20.el8
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
file@5.33-16.el8_3.1
0:5.33-20.el8
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
file@5.33-16.el8_3.1
0:5.33-20.el8
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
file@5.33-16.el8_3.1
0:5.33-20.el8
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
file@5.33-13.el8
0:5.33-20.el8
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
file@5.33-16.el8_3.1
0:5.33-20.el8
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
file@5.33-16.el8
0:5.33-20.el8
1
quay.io/openshift/origin-cli:4.66722d5041b47
file@5.33-13.el8_2.1
0:5.33-20.el8
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
file@5.33-13.el8_2.1
0:5.33-20.el8
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
file@5.33-16.el8_3.1
0:5.33-20.el8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
file@5.33-16.el8_3.1
0:5.33-20.el8
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
file@5.33-16.el8_3.1
0:5.33-20.el8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.