StackRadar

CVE-2019-20149

High

Advisory

Published 31 Mar 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.023
83rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

Validation Bypass in kind-of

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
kind-ofnpm6.0.26.0.318
OSV records
GHSA-6c8f-qphg-qjgp

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
kind-of@6.0.2
6.0.3

Open the chart page →

9,261
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
kind-of@6.0.2
6.0.3

Open the chart page →

2,513
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
kind-of@6.0.2
6.0.3

Open the chart page →

6,868
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
kind-of@6.0.2
6.0.3

Open the chart page →

5,300
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
kind-of@6.0.2
6.0.3

Open the chart page →

25,443
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
kind-of@6.0.2
6.0.3

Open the chart page →

29,901
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
kind-of@6.0.2
6.0.3

Open the chart page →

2,580
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
kind-of@6.0.2
6.0.3

Open the chart page →

25,456
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
kind-of@6.0.2
6.0.3

Open the chart page →

11,174
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
kind-of@6.0.2
6.0.3

Open the chart page →

3,005
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
kind-of@6.0.2
6.0.3

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
kind-of@6.0.2
6.0.3
ibmcom/microclimate-portal:latested5505e5c7ec
kind-of@6.0.2
6.0.3

Open the chart page →

57,669
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
kind-of@6.0.2
6.0.3

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
kind-of@6.0.2
6.0.3

Open the chart page →

3,651
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
kind-of@6.0.2
6.0.3

Open the chart page →

6,684
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
kind-of@6.0.2
6.0.3

Open the chart page →

1,866
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
kind-of@6.0.2
6.0.3

Open the chart page →

3,696
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2019-20149.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
kind-of@6.0.2
6.0.3

Open the chart page →

4,017

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gradiant/open5gs-webui:2.7.5fbd10c017541
kind-of@6.0.2
6.0.3
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
kind-of@6.0.2
6.0.3
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
kind-of@6.0.2
6.0.3
1
daskdev/dask-notebook:1.1.0052630f5ca04
kind-of@6.0.2
6.0.3
1
decayofmind/hubot:3.3.21e18e92fe694
kind-of@6.0.2
6.0.3
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
kind-of@6.0.2
6.0.3
1
getferdi/ferdi-server:1.3.26e620b85afaa
kind-of@6.0.2
6.0.3
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
kind-of@6.0.2
6.0.3
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
kind-of@6.0.2
6.0.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
kind-of@6.0.2
6.0.3
1
lavandadelpatio/frontend:latest501c3f31e0bc
kind-of@6.0.2
6.0.3
1
minddocdev/hubot:0.1.96c60b11a4fa7
kind-of@6.0.2
6.0.3
1
mozilla/sentencecollector:2.0.91da6ff5c4895
kind-of@6.0.2
6.0.3
1
ondrejsika/parking:latestb1fd497416c8
kind-of@6.0.2
6.0.3
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
kind-of@6.0.2
6.0.3
1
polonel/trudesk:1.2.60cf6513f6fe3
kind-of@6.0.2
6.0.3
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
kind-of@6.0.2
6.0.3
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
kind-of@6.0.2
6.0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.