StackRadar

CVE-2019-19221

Medium

Advisory

Published 21 Nov 2019In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libarchive security update

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
libarchiverpm3.3.2-3.el8, 3.3.2-8.el8_10:3.3.2-9.el811
libarchivedeb3.1.2-11ubuntu0.16.04.33.1.2-11ubuntu0.16.04.81
OSV records
RHSA-2020:4443UBUNTU-CVE-2019-19221
Also known as
USN-4293-1, USN-8147-1

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

9,052
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libarchive@3.1.2-11ubuntu0.16.04.3
3.1.2-11ubuntu0.16.04.8

Open the chart page →

33,963
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

25,456
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

5,792
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

12,461
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
libarchive@3.3.2-3.el8
0:3.3.2-9.el8

Open the chart page →

12,105
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

9,854
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

12,856
cloud-native-javamcouliba0.1.01 of 1See more

cloud-native-java mcouliba 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

4,979
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

11,151
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2019-19221.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8

Open the chart page →

11,437

Container images carrying it

12 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
anchore/anchore-engine:v0.7.1ed9b3badd17c
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
ctron/hawkbit-operator:0.1.48fdea8f76499
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libarchive@3.1.2-11ubuntu0.16.04.3
3.1.2-11ubuntu0.16.04.8
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
libarchive@3.3.2-3.el8
0:3.3.2-9.el8
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
quay.io/openshift/origin-cli:4.66722d5041b47
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libarchive@3.3.2-8.el8_1
0:3.3.2-9.el8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.