StackRadar

CVE-2020-10663

High

Advisory

Published 28 Apr 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
41
of 17,781 indexed, latest versions
Container images
41
deployed by those charts
Fix available
2 of 2
affected packages

Unsafe object creation in json RubyGem

Carried by container images the latest versions of 41 of 17,781 indexed charts deploy, on 41 images.

Affected packageAffected versionsFixed inImages
jsongem1.8.3, 1.8.6, 2.1.0, 2.2.02.3.041
ruby2.3deb2.3.1-2~16.04.52.3.1-2~ubuntu16.04.152
OSV records
GHSA-jphg-qwrw-7w9gUBUNTU-CVE-2020-10663
Also known as
USN-4882-1

Charts affected

41 by stars
ChartLatestAffected imagesRadar Score
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
ceticasbl/pg-ldap-sync:latest6c0aa7567145
json@2.1.0
2.3.0

Open the chart page →

52,919
efkcryptexlabsVerified publisher7.17.31 of 3See more

efk cryptexlabs 7.17.3

1 of the 3 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.12.4-debian-elasticsearch7-1.0656423b5fabb
json@2.1.0
2.3.0

Open the chart page →

1,299
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
json@2.1.0
2.3.0

Open the chart page →

18,137
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
json@2.1.0
2.3.0

Open the chart page →

4,995
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-4.1.0-312808e2dfa810
json@2.1.0
2.3.0

Open the chart page →

6,110
hbasedmwm-bigdataVerified publisher0.1.61 of 5See more

hbase dmwm-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
json@2.1.0
2.3.0

Open the chart page →

13,392
opentsdbdmwm-bigdataVerified publisher0.1.71 of 6See more

opentsdb dmwm-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
json@2.1.0
2.3.0

Open the chart page →

17,511
hbasegradiant-bigdataVerified publisher0.1.61 of 5See more

hbase gradiant-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
json@2.1.0
2.3.0

Open the chart page →

13,392
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
json@1.8.6
2.3.0

Open the chart page →

7,529
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
json@2.1.0
2.3.0

Open the chart page →

18,980
fluentdbryanalves0.1.01 of 1See more

fluentd bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
bryanalves/fluentd:0.5d3605be4b178
json@2.1.0
2.3.0

Open the chart page →

723
honeywell-exporterbryanalves0.1.11 of 1See more

honeywell-exporter bryanalves 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
json@2.1.0
2.3.0

Open the chart page →

5,437
smart-exporterbryanalves0.2.21 of 1See more

smart-exporter bryanalves 0.2.2

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
bryanalves/smart_exporter:0.2af47dfbb9413
json@2.1.0
2.3.0

Open the chart page →

4,131
fluentd-cloudwatchcloudnativeapp0.9.01 of 2See more

fluentd-cloudwatch cloudnativeapp 0.9.0

1 of the 2 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
json@2.1.0
2.3.0

Open the chart page →

1,342
puppet-forgecloudnativeapp0.1.81 of 2See more

puppet-forge cloudnativeapp 0.1.8

1 of the 2 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
hickey/puppet_forge:1.10.0c1148a09ef20
json@1.8.6
2.3.0

Open the chart page →

4,086
fluentd-kubernetes-awscloudposse0.2.11 of 2See more

fluentd-kubernetes-aws cloudposse 0.2.1

1 of the 2 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
json@2.2.0
2.3.0

Open the chart page →

1,305
coralogix-fluentddevtron1.0.31 of 1See more

coralogix-fluentd devtron 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
json@2.2.0
2.3.0

Open the chart page →

750
coralogix-fluentddevtron-labs1.0.31 of 1See more

coralogix-fluentd devtron-labs 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
json@2.2.0
2.3.0

Open the chart page →

750
opentsdbgradiant-bigdataVerified publisher0.1.71 of 6See more

opentsdb gradiant-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
json@2.1.0
2.3.0

Open the chart page →

17,511
gwangju_2-3gwangju2-30.1.01 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

1 of the 5 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
json@2.1.0
2.3.0

Open the chart page →

6,491
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
json@2.1.0
2.3.0

Open the chart page →

10,540
fluentdhelm0.2.161 of 1See more

fluentd helm 0.2.16

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.14.0-debian-elasticsearch7-1.03933cae61054
json@2.1.0
2.3.0

Open the chart page →

1,217
coralogix-fluentdhelmtest1.0.41 of 1See more

coralogix-fluentd helmtest 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
json@2.2.0
2.3.0

Open the chart page →

750
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
json@2.1.0
2.3.0

Open the chart page →

18,980
gitlabkubesphereVerified publisher4.2.36 of 17See more

gitlab kubesphere 4.2.3

6 of the 17 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
json@2.2.0
2.3.0
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
json@2.1.0
2.3.0
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
json@2.1.0
2.3.0
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
json@2.1.0
2.3.0
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
json@2.1.0
2.3.0
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
json@2.1.0
2.3.0

Open the chart page →

38,133
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-details-v1:1.13.0108d022f64f0
json@2.1.0
2.3.0

Open the chart page →

9,378
fluentd-papertrailmozilla0.2.21 of 1See more

fluentd-papertrail mozilla 0.2.2

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
json@2.1.0
2.3.0

Open the chart page →

1,001
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
json@2.1.0
2.3.0

Open the chart page →

9,542
pecanncsaVerified publisher0.6.21 of 15See more

pecan ncsa 0.6.2

1 of the 15 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
json@2.1.0
2.3.0

Open the chart page →

14,154
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
json@1.8.3
ruby2.3@2.3.1-2~16.04.5
2.3.0
2.3.1-2~ubuntu16.04.15

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
json@1.8.3
ruby2.3@2.3.1-2~16.04.5
2.3.0
2.3.1-2~ubuntu16.04.15

Open the chart page →

38,865
pact-brokerqamatic0.1.01 of 2See more

pact-broker qamatic 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.32.0-2062d6c710099
json@2.1.0
2.3.0

Open the chart page →

3,533
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
json@2.1.0
2.3.0
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
json@2.1.0
2.3.0

Open the chart page →

11,942
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2020-10663.

Open the chart page →

18,197
quarks-jobquarks0.0.124-g03faac81 of 1See more

quarks-job quarks 0.0.124-g03faac8

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
json@2.1.0
2.3.0

Open the chart page →

1,804
quarks-secretquarks0.0.677-ga060bb61 of 1See more

quarks-secret quarks 0.0.677-ga060bb6

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
json@2.1.0
2.3.0

Open the chart page →

1,814
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
json@2.1.0
2.3.0

Open the chart page →

4,010
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
json@2.1.0
2.3.0

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
json@2.1.0
2.3.0

Open the chart page →

20,462
coralogix-fluentdromholdings1.0.31 of 1See more

coralogix-fluentd romholdings 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
json@2.2.0
2.3.0

Open the chart page →

750
fluentdslamdev0.0.61 of 1See more

fluentd slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2020-10663.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
json@2.1.0
2.3.0

Open the chart page →

1,384

Container images carrying it

41 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
json@2.2.0
2.3.0
4
gradiant/hbase-base:2.0.1a1ee6de94c04
json@2.1.0
2.3.0
4
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
json@2.1.0
2.3.0
2
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
json@2.1.0
2.3.0
2
pecan/bety:5.4.1f825d480cd62
json@2.1.0
2.3.0
2
bryanalves/fluentd:0.5d3605be4b178
json@2.1.0
2.3.0
1
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
json@2.1.0
2.3.0
1
bryanalves/smart_exporter:0.2af47dfbb9413
json@2.1.0
2.3.0
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
json@2.1.0
2.3.0
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
json@2.1.0
2.3.0
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
json@2.1.0
2.3.0
1
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
json@2.1.0
2.3.0
1
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:v1.14.0-debian-elasticsearch7-1.03933cae61054
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:v1.12.4-debian-elasticsearch7-1.0656423b5fabb
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
json@2.1.0
2.3.0
1
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
json@2.2.0
2.3.0
1
hickey/puppet_forge:1.10.0c1148a09ef20
json@1.8.6
2.3.0
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
json@2.1.0
2.3.0
1
kubesphere/examples-bookinfo-details-v1:1.13.0108d022f64f0
json@2.1.0
2.3.0
1
library/logstash:7.17.817a4f64e9cf5
json@1.8.6
2.3.0
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
json@2.2.0
2.3.0
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
json@2.1.0
2.3.0
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
json@2.1.0
2.3.0
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
json@2.1.0
2.3.0
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
json@2.1.0
2.3.0
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
json@2.1.0
2.3.0
1
muluder/prograncontrollermcord:0.1.843b597a93da7
json@1.8.3
ruby2.3@2.3.1-2~16.04.5
2.3.0
2.3.1-2~ubuntu16.04.15
1
omecproject/onos-progran:1.0.05715e5648aa0
json@1.8.3
ruby2.3@2.3.1-2~16.04.5
2.3.0
2.3.1-2~ubuntu16.04.15
1
pactfoundation/pact-broker:2.32.0-2062d6c710099
json@2.1.0
2.3.0
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
json@2.1.0
2.3.0
1
zammad/zammad-docker-compose:zammad-4.1.0-312808e2dfa810
json@2.1.0
2.3.0
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
json@2.1.0
2.3.0
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
json@2.1.0
2.3.0
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
json@2.1.0
2.3.0
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
json@2.1.0
2.3.0
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
json@2.1.0
2.3.0
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
json@2.1.0
2.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.