CVE-2020-12762
HighAdvisory
Published 9 May 2020In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.8
- base score, highest
- EPSS
- 0.019
- 78th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 86
- of 17,781 indexed, latest versions
- Container images
- 85
- deployed by those charts
- Fix available
- 6 of 6
- affected packages
Red Hat Security Advisory: json-c security and bug fix update
Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 85 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| json-crpm | 0.13-1.19, 0.13.1-0.2.el8, 0.13.1-0.4.el8 | 0:0.13.1-2.el8, 0.13-3.3.1 | 51 |
| json-cdeb | 0.11-3ubuntu1.2, 0.11-4, 0.11-4ubuntu2, 0.12.1-1.1+3 more | 0.11-3ubuntu1.2+esm3, 0.11-4+deb8u1, 0.11-4ubuntu2.6, 0.12.1-1.1+deb9u1+2 more | 29 |
| json-capk | 0.13.1-r0 | 0.13.1-r1 | 1 |
| libfastjsonapk | 0.99.9-r0 | 1.2304.0-r0 | 1 |
| libfastjsonrpm | 0.99.9-1.el8 | 0:0.99.9-2.el8 | 1 |
| libfastjsondeb | 0.99.8-2, 0.99.9-1 | 0.99.8-2+deb10u1, 0.99.9-1+deb11u1 | 2 |
- OSV records
- ALPINE-CVE-2020-12762RHSA-2021:4382RLSA-2023:6976UBUNTU-CVE-2020-12762DLA-2228-1DLA-2301-1DLA-3461-1DLA-4258-1DSA-4741-1SUSE-SU-2022:0184-1
- Also known as
- DLA-2228-2, USN-4360-1, USN-4360-4
Charts affected
86 by stars
Container images carrying it
85 by charts deploying them
A fixed version is listed for 6 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| opsmx11/ | 5c50ca123d88 | json-c | 0.11-3ubuntu1.2+esm3 | 1 |
| pnnlmiscscripts/ | 155131891741 | json-c | 0:0.13.1-2.el8 | 1 |
| polyakov/ | dbcef69146b8 | json-c | 0.11-4+deb8u1 | 1 |
| resouer/ | e2f198b49ba7 | json-c | 0.11-3ubuntu1.2+esm3 | 1 |
| seldonio/ | 4e985d2006a8 | json-c | 0:0.13.1-2.el8 | 1 |
| tensorflow/ | 1e3172090703 | json-c | 0.11-4ubuntu2.6 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | json-c | 0.11-4ubuntu2.6 | 1 |
| timothyclarke/ | 40a80ced8031 | json-c | 0.11-4+deb8u1 | 1 |
| voltha/ | 59ab2a00f712 | json-c | 0.11-3ubuntu1.2+esm3 | 1 |
| ghcr.io/ | 760eee87f839 | json-c | 0.13-3.3.1 | 1 |
| ghcr.io/ | 6a1432b0d503 | json-c | 0.13-3.3.1 | 1 |
| ghcr.io/ | f059af4de8ed | json-c | 0.13-3.3.1 | 1 |
| ghcr.io/ | c7c70b527255 | json-c | 0.13-3.3.1 | 1 |
| ghcr.io/ | e24a9e0a21b6 | json-c | 0.13-3.3.1 | 1 |
| ghcr.io/ | 0cf25ed621e2 | json-c | 0:0.13.1-2.el8 | 1 |
| ghcr.io/ | 0635f17c9d2c | json-c | 0:0.13.1-2.el8 | 1 |
| ghcr.io/ | e34964e336c1 | json-c | 0:0.13.1-2.el8 | 1 |
| ghcr.io/ | 0c5a3398d1e4 | json-c | 0:0.13.1-2.el8 | 1 |
| ghcr.io/ | 8ba040e79ca0 | json-c | 0:0.13.1-2.el8 | 1 |
| ghcr.io/ | 8caf5289fe73 | json-c | 0:0.13.1-2.el8 | 1 |
| ghcr.io/ | 01d30483e4a8 | libfastjson | 1.2304.0-r0 | 1 |
| quay.io/ | cdefc81c6b2e | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 10df27bc5560 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | a3b9a07648b6 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | ea838e5b4051 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 7a4b9fedc724 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 3029dc0f1d38 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | c2851757eca4 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 107a7c73af59 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 6722d5041b47 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 0bbe8b451fa3 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | c6a934439421 | json-c | 0.11-4ubuntu2.6 | 1 |
| quay.io/ | 89ee6493af89 | json-c | 0:0.13.1-2.el8 | 1 |
| quay.io/ | 6ba82beff18e | json-c | 0:0.13.1-2.el8 | 1 |
| registry.gitlab.com/ | cf72810d33f5 | json-c | 0:0.13.1-2.el8 | 1 |