StackRadar

CVE-2020-13955

Medium

Advisory

Published 22 Apr 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
2 of 2
affected packages

Missing Authentication for Critical Function in Apache Calcite

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
calcite-coremaven1.2.0-incubating, 1.10.0, 1.14.0, 1.16.0+3 more1.26.014
calcite-druidmaven1.10.0, 1.16.01.26.07
OSV records
GHSA-hxp5-8pgq-mgv9

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
sparkmicrosoft1.0.41 of 3See more

spark microsoft 1.0.4

1 of the 3 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
calcite-core@1.2.0-incubating
1.26.0

Open the chart page →

13,738
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
calcite-core@1.18.0
1.26.0

Open the chart page →

6,048
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
calcite-core@1.16.0
calcite-druid@1.16.0
1.26.0
1.26.0

Open the chart page →

7,166
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

20,837
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
calcite-core@1.16.0
calcite-druid@1.16.0
1.26.0
1.26.0

Open the chart page →

7,335
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

8,198
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

6,882
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
calcite-core@1.14.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

6,165
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
calcite-core@1.2.0-incubating
1.26.0

Open the chart page →

14,066
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
calcite-core@1.19.0
1.26.0

Open the chart page →

16,860
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
calcite-core@1.2.0-incubating
1.26.0

Open the chart page →

6,147
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
calcite-core@1.2.0-incubating
1.26.0

Open the chart page →

5,639
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

6,882
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
calcite-core@1.2.0-incubating
1.26.0

Open the chart page →

6,147
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
calcite-core@1.17.0
1.26.0

Open the chart page →

39,349
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0

Open the chart page →

37,671
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2020-13955.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
calcite-core@1.19.0
1.26.0

Open the chart page →

15,855

Container images carrying it

14 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0
4
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
calcite-core@1.19.0
1.26.0
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0
2
gradiant/spark:2.4.4-python-alpine97657d56e927
calcite-core@1.2.0-incubating
1.26.0
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
calcite-core@1.16.0
calcite-druid@1.16.0
1.26.0
1.26.0
1
dbanda/livy:0.80ca125e68e53
calcite-core@1.2.0-incubating
1.26.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
calcite-core@1.17.0
1.26.0
1
library/solr:8.7.0d124efd81fbb
calcite-core@1.18.0
1.26.0
1
library/storm:2.4.0bd5d420506d6
calcite-core@1.14.0
calcite-druid@1.10.0
1.26.0
1.26.0
1
lightbend/spark-history-server:2.4.00bedf37f428a
calcite-core@1.2.0-incubating
1.26.0
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
calcite-core@1.10.0
calcite-druid@1.10.0
1.26.0
1.26.0
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
calcite-core@1.2.0-incubating
1.26.0
1
sslhep/hive-metastore:3.1.39e80af083079
calcite-core@1.16.0
calcite-druid@1.16.0
1.26.0
1.26.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.