CVE-2020-12243
HighAdvisory
Published 28 Apr 2020In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.044
- 91st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 352
- of 17,781 indexed, latest versions
- Container images
- 232
- deployed by those charts
- Fix available
- 4 of 4
- affected packages
Red Hat Security Advisory: openldap security update
Carried by container images the latest versions of 352 of 17,781 indexed charts deploy, on 232 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openldapdeb | 2.4.31-1+nmu2ubuntu8, 2.4.31-1+nmu2ubuntu8.4, 2.4.31-1+nmu2ubuntu8.5, 2.4.40+dfsg-1+deb8u2+18 more | 2.4.31-1+nmu2ubuntu8.5+esm2, 2.4.40+dfsg-1+deb8u6, 2.4.42+dfsg-2ubuntu3.8, 2.4.44+dfsg-5+deb9u4+2 more | 206 |
| openldaprpm | 2.4.44-21.el7_6 | 0:2.4.44-22.el7 | 18 |
| openldapapk | 2.4.47-r2, 2.4.48-r0, 2.4.48-r1 | 2.4.48-r1, 2.4.48-r2 | 6 |
| openldap2rpm | 2.4.46-lp151.10.3.1 | 2.4.46-lp151.10.9.1 | 2 |
- OSV records
- ALPINE-CVE-2020-12243RHSA-2020:4041UBUNTU-CVE-2020-12243DLA-2199-1DSA-4666-1openSUSE-SU-2020:0647-1
- Also known as
- USN-4352-1, USN-4352-2
Charts affected
352 by stars
Container images carrying it
232 by charts deploying them
A fixed version is listed for 4 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| raykrueger/ | c8baf3de57bb | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| resouer/ | e2f198b49ba7 | openldap | 2.4.31-1+nmu2ubuntu8.5+esm2 | 1 |
| richardchesterwood/ | 0b540a28f5a6 | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| richardchesterwood/ | 36c43961214c | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| royalwang/ | df99e2499f91 | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| rundeck/ | b13e8059ad72 | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| scrapinghub/ | a5f89bc84606 | openldap | 2.4.45+dfsg-1ubuntu1.5 | 1 |
| seldonio/ | 1d0da98a2d76 | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| sismics/ | f4b0ef019cf1 | openldap | 2.4.45+dfsg-1ubuntu1.5 | 1 |
| sorintlab/ | 36b45c0f97fc | openldap | 2.4.47+dfsg-3+deb10u2 | 1 |
| stakater/ | 4f8e409f30c2 | openldap | 2.4.40+dfsg-1+deb8u6 | 1 |
| svtechnmaa/ | e19aba397c1f | openldap | 2.4.47+dfsg-3+deb10u2 | 1 |
| tensorflow/ | 1e3172090703 | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| testhubio/ | 56badee134b9 | openldap | 2.4.47+dfsg-3+deb10u2 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| timothyclarke/ | 40a80ced8031 | openldap | 2.4.40+dfsg-1+deb8u6 | 1 |
| tpdock/ | 3da600c95a49 | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| voltha/ | 59ab2a00f712 | openldap | 2.4.31-1+nmu2ubuntu8.5+esm2 | 1 |
| vromero/ | 408d6a46b153 | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| weblate/ | 82848df56ecd | openldap | 2.4.47+dfsg-3+deb10u2 | 1 |
| wiremind/ | 4dea42c8166c | openldap | 2.4.47+dfsg-3+deb10u2 | 1 |
| yandex/ | d210dc69321e | openldap | 2.4.45+dfsg-1ubuntu1.5 | 1 |
| zenko/ | 386a1f48ec0e | openldap | 2.4.40+dfsg-1+deb8u6 | 1 |
| gcr.io/ | 809338a69bd5 | openldap | 2.4.45+dfsg-1ubuntu1.5 | 1 |
| gcr.io/ | 10f4dbc8eeeb | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| gcr.io/ | cb5c1bddd1b5 | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| gcr.io/ | 5ea7b7f3632a | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| gcr.io/ | 8f9ff98fdbef | openldap | 2.4.42+dfsg-2ubuntu3.8 | 1 |
| ghcr.io/ | 451706815103 | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| ghcr.io/ | 763daf9caf8e | openldap | 2.4.44+dfsg-5+deb9u4 | 1 |
| quay.io/ | 86b71e90319f | openldap | 2.4.40+dfsg-1+deb8u6 | 1 |
| quay.io/ | 9a8d95ca0bd9 | openldap | 2.4.47+dfsg-3+deb10u2 | 1 |