StackRadar

CVE-2020-11022

Medium

Advisory

Published 29 Apr 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.990
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
24
deployed by those charts
Fix available
4 of 4
affected packages

Potential XSS vulnerability in jQuery

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
jquerydeb1.11.3+dfsg-4, 3.2.1-1, 3.3.1~dfsg-31.11.3+dfsg-4ubuntu0.1~esm1, 3.2.1-1ubuntu0.1~esm1, 3.3.1~dfsg-3ubuntu0.111
jquerynpm2.0.0pre, 2.2.1, 2.2.4, 3.3.1+1 more3.5.08
maximebf/debugbarcomposerv1.11.1, v1.15.1, v1.18.0, v1.18.21.19.04
jquery-railsgem4.2.24.4.01
OSV records
GHSA-gxr4-xjj5-5px2UBUNTU-CVE-2020-11022
Also known as
BIT-drupal-2020-11022, USN-7246-1, USN-7622-1

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
maximebf/debugbar@v1.18.0
1.19.0

Open the chart page →

18,509
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
jquery-rails@4.2.2
4.4.0

Open the chart page →

18,137
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1

Open the chart page →

113,791
smarter-demosmarterOfficialVerified publisher0.1.51 of 7See more

smarter-demo smarter 0.1.5

1 of the 7 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1

Open the chart page →

45,832
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
jquery@3.4.1
3.5.0

Open the chart page →

7,517
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
jquery@2.0.0pre
3.5.0

Open the chart page →

3,437
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
jquery@2.2.4
3.5.0

Open the chart page →

2,783
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
jquery@3.3.1
3.5.0

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
jquery@1.11.3+dfsg-4
1.11.3+dfsg-4ubuntu0.1~esm1

Open the chart page →

27,417
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
jquery@3.2.1-1
3.2.1-1ubuntu0.1~esm1

Open the chart page →

27,728
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
jquery@3.4.1
3.5.0

Open the chart page →

11,174
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
jquery@3.3.1
3.5.0

Open the chart page →

1,043
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
maximebf/debugbar@v1.15.1
1.19.0

Open the chart page →

5,332
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
jquery@3.4.1
3.5.0

Open the chart page →

7,929
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
maximebf/debugbar@v1.18.2
1.19.0

Open the chart page →

12,813
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
jquery@1.11.3+dfsg-4
1.11.3+dfsg-4ubuntu0.1~esm1

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
jquery@1.11.3+dfsg-4
1.11.3+dfsg-4ubuntu0.1~esm1

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
jquery@3.2.1-1
3.2.1-1ubuntu0.1~esm1

Open the chart page →

36,215
podcast-helmpodcastwala-helm0.1.01 of 2See more

podcast-helm podcastwala-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
shivani446/podcastwala-php:v1c0d07b7b4c8d
maximebf/debugbar@v1.11.1
1.19.0

Open the chart page →

621
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-11022.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
jquery@2.2.1
3.5.0

Open the chart page →

5,215

Container images carrying it

24 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
akaunting/akaunting:3.0.1552811b36ec3a
maximebf/debugbar@v1.18.2
1.19.0
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
jquery@3.4.1
3.5.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
jquery@3.4.1
3.5.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
jquery@3.3.1
3.5.0
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
jquery@1.11.3+dfsg-4
1.11.3+dfsg-4ubuntu0.1~esm1
1
gristlabs/grist:0.7.96e71b1914a7e
jquery@2.2.1
3.5.0
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
jquery-rails@4.2.2
4.4.0
1
linuxserver/grocy:version-v3.1.3291296e66c2a
jquery@3.3.1
3.5.0
1
muluder/prograncontrollermcord:0.1.843b597a93da7
jquery@1.11.3+dfsg-4
1.11.3+dfsg-4ubuntu0.1~esm1
1
omecproject/onos-progran:1.0.05715e5648aa0
jquery@1.11.3+dfsg-4
1.11.3+dfsg-4ubuntu0.1~esm1
1
opendatacube/wms:latest1b90cdf68831
jquery@3.2.1-1
3.2.1-1ubuntu0.1~esm1
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
jquery@2.0.0pre
3.5.0
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
jquery@3.2.1-1
3.2.1-1ubuntu0.1~esm1
1
shivani446/podcastwala-php:v1c0d07b7b4c8d
maximebf/debugbar@v1.11.1
1.19.0
1
snipe/snipe-it:v6.0.1455fb7636a98c
maximebf/debugbar@v1.18.0
1.19.0
1
testhubio/testhub-frontend:on-preme86c2db53be8
jquery@3.4.1
3.5.0
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
maximebf/debugbar@v1.15.1
1.19.0
1
zazuko/trifid:2.3.7054be137de70
jquery@2.2.4
3.5.0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
jquery@3.3.1~dfsg-3
3.3.1~dfsg-3ubuntu0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.