StackRadar

CVE-2020-13936

High

Advisory

Published 6 Jan 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.227
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
35
of 17,781 indexed, latest versions
Container images
33
deployed by those charts
Fix available
None
affected package

Sandbox Bypass in Apache Velocity Engine

Carried by container images the latest versions of 35 of 17,781 indexed charts deploy, on 33 images.

Affected packageAffected versionsFixed inImages
velocitymaven1.5, 1.6.3, 1.6.4, 1.6.4-atlassian-21+4 moreno fix listed33
OSV records
GHSA-59j4-wjwp-mw9m

Charts affected

35 by stars
ChartLatestAffected imagesRadar Score
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
velocity@1.6.4-atlassian-jakarta-42
no fix listed

Open the chart page →

1,490
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
velocity@1.6.4-atlassian-jakarta-41
no fix listed

Open the chart page →

1,444
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
velocity@1.6.4-atlassian-jakarta-41
no fix listed

Open the chart page →

1,415
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
velocity@1.6.4-atlassian-25
no fix listed

Open the chart page →

8,636
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/bamboo:12.1.114af4bb6c8d46
velocity@1.6.4-atlassian-jakarta-42
no fix listed

Open the chart page →

2,031
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
velocity@1.7
no fix listed

Open the chart page →

7,166
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
velocity@1.5
no fix listed
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
velocity@1.5
no fix listed

Open the chart page →

20,837
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
velocity@1.7
no fix listed

Open the chart page →

7,335
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
velocity@1.5
no fix listed

Open the chart page →

8,198
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
velocity@1.7
no fix listed

Open the chart page →

10,730
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
velocity@1.5
no fix listed

Open the chart page →

6,882
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
velocity@1.5
no fix listed

Open the chart page →

6,165
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
velocity@1.7
no fix listed

Open the chart page →

4,145
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
velocity@1.7
no fix listed

Open the chart page →

5,806
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
velocity@1.7
no fix listed

Open the chart page →

9,144
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
velocity@1.7
no fix listed

Open the chart page →

8,245
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
velocity@1.5
no fix listed
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
velocity@1.5
no fix listed

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
velocity@1.5
no fix listed

Open the chart page →

6,882
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
velocity@1.7
no fix listed

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
velocity@1.5
no fix listed
ibmcom/microclimate-theia:lateste17bdccc5030
velocity@1.5
no fix listed

Open the chart page →

57,669
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
velocity@1.6.3
no fix listed

Open the chart page →

1,754
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
velocity@1.7
no fix listed

Open the chart page →

12,856
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
velocity@1.6.4
no fix listed

Open the chart page →

4,664
tapm-componentkubebb5.7.12 of 3See more

tapm-component kubebb 5.7.1

2 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
velocity@1.6.4
no fix listed
refar/apm-operator-server:v5.7.1e5490f050f9f
velocity@1.6.4
no fix listed

Open the chart page →

10,264
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
velocity@1.6.4
no fix listed

Open the chart page →

6,490
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
velocity@1.7
no fix listed

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
velocity@1.7
no fix listed

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
velocity@1.7
no fix listed

Open the chart page →

10,603
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
velocity@1.6.4-atlassian-25
no fix listed

Open the chart page →

5,663
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
velocity@1.7
no fix listed

Open the chart page →

6,237
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
reportportal/service-authorization:5.7.09e73114dbd15
velocity@1.7
no fix listed

Open the chart page →

25,737
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
velocity@1.7
no fix listed

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
velocity@1.6.4-atlassian-21
no fix listed

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
velocity@1.6.4-atlassian-21
no fix listed

Open the chart page →

13,079
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-13936.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
velocity@1.7
no fix listed

Open the chart page →

5,806

Container images carrying it

33 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
velocity@1.5
no fix listed
4
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
velocity@1.7
no fix listed
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
velocity@1.5
no fix listed
2
opensearchproject/opensearch:1.1.0967d7f57f72f
velocity@1.7
no fix listed
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
velocity@1.7
no fix listed
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
velocity@1.7
no fix listed
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
velocity@1.7
no fix listed
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
velocity@1.7
no fix listed
1
atlassian/bamboo:12.1.114af4bb6c8d46
velocity@1.6.4-atlassian-jakarta-42
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
velocity@1.6.4-atlassian-jakarta-41
no fix listed
1
atlassian/confluence-server:7.10.03b9222ab32ef
velocity@1.6.4-atlassian-21
no fix listed
1
atlassian/crowd:7.2.3c81cc7d6bc9e
velocity@1.6.4-atlassian-jakarta-41
no fix listed
1
atlassian/crowd:5.2.2ebf761c7d437
velocity@1.6.4-atlassian-25
no fix listed
1
atlassian/jira-software:8.14.037bc46cbec1a
velocity@1.6.4-atlassian-21
no fix listed
1
atlassian/jira-software:9.7.264a75aa4ec4e
velocity@1.6.4-atlassian-25
no fix listed
1
atlassian/jira-software:11.3.11e5548cd4eea8
velocity@1.6.4-atlassian-jakarta-42
no fix listed
1
easypi/openrefine:3.7.0d2950a36a576
velocity@1.6.3
no fix listed
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
velocity@1.7
no fix listed
1
farberg/apache-knox-docker:1.6.14b4a22487394
velocity@1.7
no fix listed
1
gocd/gocd-server:v19.3.02da45cb09d57
velocity@1.7
no fix listed
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
velocity@1.7
no fix listed
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
velocity@1.5
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
velocity@1.5
no fix listed
1
kubebb/gateway-api:v5.6.04d062f20309c
velocity@1.6.4
no fix listed
1
kubebb/mesh-api:v5.7.0a3879931dfa1
velocity@1.6.4
no fix listed
1
library/storm:2.4.0bd5d420506d6
velocity@1.5
no fix listed
1
refar/apm-api:v5.7.1241373fa2972
velocity@1.6.4
no fix listed
1
refar/apm-operator-server:v5.7.1e5490f050f9f
velocity@1.6.4
no fix listed
1
reportportal/service-authorization:5.7.09e73114dbd15
velocity@1.7
no fix listed
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
velocity@1.5
no fix listed
1
sslhep/hive-metastore:3.1.39e80af083079
velocity@1.7
no fix listed
1
xetusoss/archiva:v2.2.588f25242b9ee
velocity@1.7
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
velocity@1.7
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.