StackRadar

CVE-2020-13949

High

Advisory

Published 12 Mar 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
41
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
1 of 1
affected package

Uncontrolled Resource Consumption in Apache Thrift

Carried by container images the latest versions of 41 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
libthriftmaven0.9.3, 0.9.3-1, 0.10.0, 0.12.0+1 more0.14.034
OSV records
GHSA-g2fg-mr77-6vrm
Also known as
BIT-thrift-2020-13949

Charts affected

41 by stars
ChartLatestAffected imagesRadar Score
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
libthrift@0.13.0
0.14.0

Open the chart page →

3,229
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
libthrift@0.13.0
0.14.0

Open the chart page →

3,812
sparkmicrosoft1.0.41 of 3See more

spark microsoft 1.0.4

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
libthrift@0.9.3
0.14.0

Open the chart page →

13,738
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
libthrift@0.13.0
0.14.0

Open the chart page →

6,048
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
libthrift@0.13.0
0.14.0

Open the chart page →

7,930
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
libthrift@0.9.3
0.14.0

Open the chart page →

7,166
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.14.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libthrift@0.9.3
0.14.0

Open the chart page →

20,837
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
libthrift@0.9.3
0.14.0

Open the chart page →

7,335
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
libthrift@0.9.3
0.14.0

Open the chart page →

8,198
hbasedmwm-bigdataVerified publisher0.1.61 of 5See more

hbase dmwm-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.14.0

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.14.0

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.71 of 6See more

opentsdb dmwm-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.14.0

Open the chart page →

17,511
hbasegradiant-bigdataVerified publisher0.1.61 of 5See more

hbase gradiant-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.14.0

Open the chart page →

13,392
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
libthrift@0.13.0
0.14.0

Open the chart page →

6,165
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
libthrift@0.9.3
0.14.0

Open the chart page →

12,019
snowplowt3n0.0.11 of 1See more

snowplow t3n 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
libthrift@0.13.0
0.14.0

Open the chart page →

2,269
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libthrift@0.12.0
0.14.0

Open the chart page →

7,835
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
libthrift@0.13.0
0.14.0

Open the chart page →

5,277
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
libthrift@0.9.3
0.14.0

Open the chart page →

14,066
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
libthrift@0.13.0
0.14.0

Open the chart page →

8,245
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
libthrift@0.9.3
0.14.0

Open the chart page →

6,147
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
libthrift@0.9.3
0.14.0

Open the chart page →

5,639
accumulogaffer2.2.11 of 4See more

accumulo gaffer 2.2.1

1 of the 4 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
libthrift@0.12.0
0.14.0

Open the chart page →

16,892
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
libthrift@0.13.0
0.14.0

Open the chart page →

34,754
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.14.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libthrift@0.9.3
0.14.0

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.14.0

Open the chart page →

6,882
opentsdbgradiant-bigdataVerified publisher0.1.71 of 6See more

opentsdb gradiant-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.14.0

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
libthrift@0.9.3
0.14.0

Open the chart page →

6,147
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libthrift@0.12.0
0.14.0

Open the chart page →

4,556
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
libthrift@0.13.0
0.14.0

Open the chart page →

8,541
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
libthrift@0.13.0
0.14.0

Open the chart page →

37,671
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
libthrift@0.10.0
0.14.0

Open the chart page →

43,341
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
libthrift@0.13.0
0.14.0

Open the chart page →

3,633
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
libthrift@0.9.3
0.14.0

Open the chart page →

8,540
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
libthrift@0.9.3
0.14.0

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
libthrift@0.9.3
0.14.0

Open the chart page →

38,865
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
libthrift@0.9.3
0.14.0

Open the chart page →

9,606
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
libthrift@0.9.3-1
0.14.0

Open the chart page →

13,767
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
libthrift@0.12.0
0.14.0

Open the chart page →

4,538
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
libthrift@0.10.0
0.14.0

Open the chart page →

4,649
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2020-13949.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libthrift@0.13.0
0.14.0

Open the chart page →

28,605

Container images carrying it

34 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
libthrift@0.9.3
0.14.0
4
gradiant/hbase-base:2.0.1a1ee6de94c04
libthrift@0.9.3
0.14.0
4
apache/druid:37.0.00116fb802786
libthrift@0.13.0
0.14.0
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libthrift@0.9.3
0.14.0
2
gradiant/spark:2.4.4-python-alpine97657d56e927
libthrift@0.9.3
0.14.0
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
libthrift@0.9.3
0.14.0
1
apache/druid:29.0.10cef139b6bf1
libthrift@0.13.0
0.14.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libthrift@0.12.0
0.14.0
1
apache/iotdb:0.11.28647309f95d1
libthrift@0.13.0
0.14.0
1
datappeal/hive-metastore:lateste38c085a3567
libthrift@0.9.3
0.14.0
1
dbanda/livy:0.80ca125e68e53
libthrift@0.9.3
0.14.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
libthrift@0.13.0
0.14.0
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
libthrift@0.13.0
0.14.0
1
gchq/accumulo:2.0.1c460bb587d6d
libthrift@0.12.0
0.14.0
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
libthrift@0.13.0
0.14.0
1
library/solr:8.7.0d124efd81fbb
libthrift@0.13.0
0.14.0
1
library/storm:2.4.0bd5d420506d6
libthrift@0.13.0
0.14.0
1
lightbend/spark-history-server:2.4.00bedf37f428a
libthrift@0.9.3
0.14.0
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
libthrift@0.10.0
0.14.0
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libthrift@0.9.3
0.14.0
1
omecproject/onos-progran:1.0.05715e5648aa0
libthrift@0.9.3
0.14.0
1
openzipkin/zipkin:2.21.060c3970df479
libthrift@0.13.0
0.14.0
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
libthrift@0.12.0
0.14.0
1
owasp/dependency-track:3.8.0efc65e702ee1
libthrift@0.13.0
0.14.0
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
libthrift@0.9.3
0.14.0
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
libthrift@0.9.3
0.14.0
1
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
libthrift@0.13.0
0.14.0
1
sslhep/hive-metastore:3.1.39e80af083079
libthrift@0.9.3
0.14.0
1
trinodb/trino:405ee80ab5eeab2
libthrift@0.9.3-1
0.14.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
libthrift@0.12.0
0.14.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
libthrift@0.9.3
0.14.0
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
libthrift@0.10.0
0.14.0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
libthrift@0.9.3
0.14.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libthrift@0.13.0
0.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.