StackRadar

CVE-2020-11008

High

Advisory

Published 20 Apr 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.039
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: git security update

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
gitdeb1:2.1.4-2.1+deb8u2, 1:2.1.4-2.1+deb8u3, 1:2.1.4-2.1+deb8u5, 1:2.1.4-2.1+deb8u6+16 more1:2.1.4-2.1+deb8u10, 1:2.7.4-0ubuntu1.9, 1:2.11.0-3+deb9u7, 1:2.17.1-1ubuntu0.7+1 more76
gitapk2.18.1-r0, 2.20.1-r0, 2.20.2-r0, 2.24.1-r02.18.4-r0, 2.20.4-r0, 2.24.3-r013
gitrpm1.8.3.1-20.el70:1.8.3.1-23.el7_82
OSV records
ALPINE-CVE-2020-11008RHSA-2020:2337UBUNTU-CVE-2020-11008DLA-2182-1DSA-4659-1
Also known as
USN-4334-1

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9

Open the chart page →

25,769
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
git@1:2.1.4-2.1+deb8u5
1:2.1.4-2.1+deb8u10

Open the chart page →

3,116
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7

Open the chart page →

11,841
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7

Open the chart page →

4,967
pi-holet3n1.0.01 of 1See more

pi-hole t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
pihole/pihole:v4.48c172c4cf344
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7

Open the chart page →

1,373
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7

Open the chart page →

8,262
workerappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7

Open the chart page →

3,329
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7

Open the chart page →

8,262
workerappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7

Open the chart page →

3,329
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2020-11008.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
git@2.18.1-r0
2.18.4-r0

Open the chart page →

1,572

Container images carrying it

91 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9
11
oomk8s/readiness-check:2.0.07daa08b81954
git@1:2.7.4-0ubuntu1.3
1:2.7.4-0ubuntu1.9
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
git@1:2.7.4-0ubuntu1.4
1:2.7.4-0ubuntu1.9
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
git@1:2.7.4-0ubuntu1.6
1:2.7.4-0ubuntu1.9
4
kodekloud/examplevotingapp_worker:v1741e3aaaa812
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7
4
anapsix/satisfyfae78e3809e9
git@2.18.1-r0
2.18.4-r0
3
mautic/mautic:2.13-apachea954c5868d76
git@1:2.1.4-2.1+deb8u5
1:2.1.4-2.1+deb8u10
3
amancevice/superset:0.35.212a0a9e66550
git@1:2.20.1-2+deb10u1
1:2.20.1-2+deb10u3
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7
2
migmartri/prerender:latest486aacfd5aa9
git@1:2.1.4-2.1+deb8u2
1:2.1.4-2.1+deb8u10
2
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
git@1:2.11.0-3+deb9u3
1:2.11.0-3+deb9u7
2
neilpeterson/azure-vote-front:v384062718347c
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7
2
statsd/statsd:v0.8.6dab129e74c25
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
2
ujamii/prometheus-sentry-exporter:0.5.06243197349e1
git@1:2.20.1-2
1:2.20.1-2+deb10u3
2
a5huynh/oauth2_proxy:2.20c7307d31ca8
git@1:2.1.4-2.1+deb8u2
1:2.1.4-2.1+deb8u10
1
amancevice/superset:0.28.1c8c04bfe3d66
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
git@1:2.1.4-2.1+deb8u2
1:2.1.4-2.1+deb8u10
1
argoproj/argocd:v1.2.1b0230853357d
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
1
billimek/comcastusage-for-influxdb:latest801bba1228ac
git@1:2.1.4-2.1+deb8u5
1:2.1.4-2.1+deb8u10
1
binford2k/showoff:0.20.2a64937052ce7
git@2.20.2-r0
2.20.4-r0
1
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
git@1:2.11.0-3+deb9u2
1:2.11.0-3+deb9u7
1
bryanalves/smart_exporter:0.2af47dfbb9413
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
1
camptocamp/ekorre:0.1.035c91d5fda04
git@1:2.20.1-2+deb10u1
1:2.20.1-2+deb10u3
1
camptocamp/imap-mailbox-exporter:latest9dec019e4c62
git@1:2.1.4-2.1+deb8u3
1:2.1.4-2.1+deb8u10
1
camptocamp/ldap-search-exporter:latest5e55370dd292
git@1:2.1.4-2.1+deb8u3
1:2.1.4-2.1+deb8u10
1
camptocamp/pghoard:10bff736b15623
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
1
cdignam/kodiak:v0.54.05a6a55b39cee
git@1:2.20.1-2
1:2.20.1-2+deb10u3
1
cheyang/distributed-tf:1.6.046cc34755493
git@1:2.7.4-0ubuntu1.3
1:2.7.4-0ubuntu1.9
1
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7
1
confluentinc/cp-kafka:5.4.01bbda887bc53
git@1:2.1.4-2.1+deb8u8
1:2.1.4-2.1+deb8u10
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
git@1:2.1.4-2.1+deb8u7
1:2.1.4-2.1+deb8u10
1
daskdev/dask:1.1.04ecd7bc35500
git@1:2.11.0-3+deb9u3
1:2.11.0-3+deb9u7
1
daskdev/dask-notebook:1.1.0052630f5ca04
git@1:2.17.1-1ubuntu0.4
1:2.17.1-1ubuntu0.7
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7
1
devspacecloud/manager:0.3.349c397413f7b
git@2.24.1-r0
2.24.3-r0
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
git@1:2.7.4-0ubuntu1.3
1:2.7.4-0ubuntu1.9
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
git@1:2.1.4-2.1+deb8u6
1:2.1.4-2.1+deb8u10
1
gitlab/gitlab-runner:alpine-v12.3.0a83c15bda342
git@2.20.1-r0
2.20.4-r0
1
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
git@2.20.1-r0
2.20.4-r0
1
gocd/gocd-server:v19.3.02da45cb09d57
git@2.20.1-r0
2.20.4-r0
1
gomods/athens:v0.8.1d714c7ff0231
git@2.24.1-r0
2.24.3-r0
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
git@1:2.11.0-3+deb9u5
1:2.11.0-3+deb9u7
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
git@1:2.11.0-3+deb9u4
1:2.11.0-3+deb9u7
1
hickey/puppet_forge:1.10.0c1148a09ef20
git@1:2.1.4-2.1+deb8u5
1:2.1.4-2.1+deb8u10
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
git@1:2.7.4-0ubuntu1.4
1:2.7.4-0ubuntu1.9
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
git@1.8.3.1-20.el7
0:1.8.3.1-23.el7_8
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
git@1.8.3.1-20.el7
0:1.8.3.1-23.el7_8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.