StackRadar

CVE-2020-13956

Medium

Advisory

Published 3 Jun 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.090
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
190
of 17,781 indexed, latest versions
Container images
217
deployed by those charts
Fix available
28 of 28
affected packages

Cross-site scripting in Apache HttpClient

Carried by container images the latest versions of 190 of 17,781 indexed charts deploy, on 217 images.

Affected packageAffected versionsFixed inImages
httpclientmaven4.0.1, 4.0.2, 4.2.5, 4.2.6+19 more4.5.13217
aopalliancerpm1.0-20.module+el8.3.0+6804+157bd82e0:1.0-20.module+el8.6.0+13337+afcb49ec5
apache-commons-clirpm1.4-7.module+el8.3.0+6804+157bd82e0:1.4-7.module+el8.6.0+13337+afcb49ec5
apache-commons-codecrpm1.13-3.module+el8.3.0+6804+157bd82e0:1.13-3.module+el8.6.0+13337+afcb49ec5
apache-commons-iorpm1:2.6-6.module+el8.3.0+6804+157bd82e1:2.6-6.module+el8.6.0+13337+afcb49ec5
apache-commons-lang3rpm3.9-4.module+el8.3.0+6804+157bd82e0:3.9-4.module+el8.6.0+13337+afcb49ec5
atinjectrpm1-31.20100611svn86.module+el8.3.0+6804+157bd82e0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec5
cdi-apirpm2.0.1-3.module+el8.3.0+6804+157bd82e0:2.0.1-3.module+el8.6.0+13337+afcb49ec5
geronimo-annotationrpm1.0-26.module+el8.3.0+6804+157bd82e0:1.0-26.module+el8.6.0+13337+afcb49ec5
google-guicerpm4.2.2-4.module+el8.3.0+6804+157bd82e0:4.2.2-4.module+el8.6.0+13337+afcb49ec5
guavarpm28.1-3.module+el8.3.0+6804+157bd82e0:28.1-3.module+el8.6.0+13337+afcb49ec5
httpcomponents-clientrpm4.5.10-3.module+el8.3.0+6804+157bd82e0:4.5.10-4.module+el8.6.0+13337+afcb49ec5
httpcomponents-corerpm4.4.12-3.module+el8.3.0+6804+157bd82e0:4.4.12-3.module+el8.6.0+13337+afcb49ec5
jansirpm1.18-4.module+el8.3.0+6804+157bd82e0:1.18-4.module+el8.6.0+13337+afcb49ec5
jsouprpm1.12.1-3.module+el8.3.0+6804+157bd82e0:1.12.1-3.module+el8.6.0+13337+afcb49ec5
jsr-305rpm0-0.25.20130910svn.module+el8.3.0+6804+157bd82e0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec5
mavenrpm1:3.6.2-6.module+el8.4.0+9250+1786af371:3.6.2-7.module+el8.6.0+13337+afcb49ec5
maven-resolverrpm1.4.1-3.module+el8.3.0+6804+157bd82e0:1.4.1-3.module+el8.6.0+13337+afcb49ec5
maven-shared-utilsrpm3.2.1-0.4.module+el8.3.0+6804+157bd82e0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec5
maven-wagonrpm3.3.4-2.module+el8.3.0+6804+157bd82e0:3.3.4-2.module+el8.6.0+13337+afcb49ec5
plexus-cipherrpm1.7-17.module+el8.3.0+6804+157bd82e0:1.7-17.module+el8.6.0+13337+afcb49ec5
plexus-classworldsrpm2.6.0-4.module+el8.3.0+6804+157bd82e0:2.6.0-4.module+el8.6.0+13337+afcb49ec5
plexus-containersrpm2.1.0-2.module+el8.3.0+6804+157bd82e0:2.1.0-2.module+el8.6.0+13337+afcb49ec5
plexus-interpolationrpm1.26-3.module+el8.3.0+6804+157bd82e0:1.26-3.module+el8.6.0+13337+afcb49ec5
plexus-sec-dispatcherrpm1.4-29.module+el8.3.0+6804+157bd82e0:1.4-29.module+el8.6.0+13337+afcb49ec5
plexus-utilsrpm3.3.0-3.module+el8.3.0+6804+157bd82e0:3.3.0-3.module+el8.6.0+13337+afcb49ec5
sisurpm0.3.4-2.module+el8.3.0+6804+157bd82e0:0.3.4-2.module+el8.6.0+13337+afcb49ec5
slf4jrpm1.7.28-3.module+el8.3.0+6804+157bd82e0:1.7.28-3.module+el8.6.0+13337+afcb49ec5
OSV records
GHSA-7r82-7xv7-xcpjRHSA-2022:1860

Charts affected

190 by stars
ChartLatestAffected imagesRadar Score
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
httpclient@4.5.2
4.5.13

Open the chart page →

3,812
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
httpclient@4.5.2
4.5.13

Open the chart page →

10,732
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
httpclient@4.5.2
4.5.13
dbanda/spark:2.4.6d0e6367876ae
httpclient@4.5.2
4.5.13

Open the chart page →

13,738
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
httpclient@4.5.12
4.5.13

Open the chart page →

6,048
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient@4.5.5
4.5.13

Open the chart page →

7,268
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
httpclient@4.5.2
4.5.13

Open the chart page →

7,930
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
httpclient@4.3.5
4.5.13

Open the chart page →

10,530
flinkriskfocus0.2.01 of 1See more

flink riskfocus 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/flink:1.11.2-scala_2.121fe4fb22a2a5
httpclient@4.5.3
4.5.13

Open the chart page →

3,235
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
httpclient@4.5.10
4.5.13
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
httpclient@4.5.10
4.5.13

Open the chart page →

8,698
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
httpclient@4.5.2
4.5.13

Open the chart page →

7,166
hdfsdmwm-bigdataVerified publisher1.0.11 of 2See more

hdfs dmwm-bigdata 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/hdfs:3.2.2e3bf364fe713
httpclient@4.5.5
4.5.13

Open the chart page →

7,948
hivedmwm-bigdataVerified publisher0.1.63 of 5See more

hive dmwm-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
httpclient@4.2.5
4.5.13
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
httpclient@4.2.5
4.5.13

Open the chart page →

20,837
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
httpclient@4.5.2
4.5.13

Open the chart page →

7,335
cratedbhmdmph2.0.31 of 2See more

cratedb hmdmph 2.0.3

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/crate:4.7.0c7984a05e15b
httpclient@4.5.12
4.5.13

Open the chart page →

1,335
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
httpclient@4.5.7
4.5.13
apache/skywalking-ui:8.1.067d50e4deff4
httpclient@4.5.3
4.5.13

Open the chart page →

18,042
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
httpclient@4.5.2
4.5.13

Open the chart page →

8,198
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
httpclient@4.5.2
4.5.13

Open the chart page →

4,419
soarv113assist-iot-cybersecurity-monitoring-soar0.1.32 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

2 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
httpclient@4.5.10
4.5.13
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
httpclient@4.5.10
4.5.13

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
httpclient@4.5.3
4.5.13

Open the chart page →

10,730
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
httpclient@4.5.12
4.5.13

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
httpclient@4.5.12
4.5.13

Open the chart page →

84,444
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
httpclient@4.5.3
4.5.13

Open the chart page →

4,532
hadoopcloudnativeapp1.1.01 of 1See more

hadoop cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
httpclient@4.5.2
4.5.13

Open the chart page →

5,772
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
httpclient@4.5.1
4.5.13

Open the chart page →

7,891
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
httpclient@4.5.10
4.5.13

Open the chart page →

38,346
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
httpclient@4.5.6
4.5.13

Open the chart page →

2,140
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
httpclient@4.5.10
4.5.13

Open the chart page →

6,110
hbasedmwm-bigdataVerified publisher0.1.62 of 5See more

hbase dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
httpclient@4.5.3
4.5.13
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
httpclient@4.2.5
4.5.13

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.73 of 6See more

opentsdb dmwm-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
httpclient@4.5.3
4.5.13
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13
gradiant/opentsdb:2.4.0c33d53913869
httpclient@4.3.1
4.5.13

Open the chart page →

17,511
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
httpclient@4.5.10
4.5.13

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
httpclient@4.5.6
4.5.13

Open the chart page →

6,531
elasticsearch-dataempathyco0.2.01 of 2See more

elasticsearch-data empathyco 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
httpclient@4.5.2
4.5.13

Open the chart page →

3,703
elasticsearch-masterempathyco0.3.01 of 2See more

elasticsearch-master empathyco 0.3.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
httpclient@4.5.2
4.5.13

Open the chart page →

3,703
enavenav-service-architectureVerified publisher0.0.77 of 10See more

enav enav-service-architecture 0.0.7

7 of the 10 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
httpclient@4.5.3
4.5.13
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
httpclient@4.5.3
4.5.13
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
httpclient@4.5.3
4.5.13
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
httpclient@4.5.3
4.5.13
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
httpclient@4.5.3
4.5.13
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
httpclient@4.5.3
4.5.13
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
httpclient@4.5.3
4.5.13

Open the chart page →

15,860
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
httpclient@4.5.7
4.5.13

Open the chart page →

11,553
hbasegradiant-bigdataVerified publisher0.1.62 of 5See more

hbase gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
httpclient@4.5.3
4.5.13
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13

Open the chart page →

13,392
amgraviteeioVerified publisher4.12.62 of 3See more

am graviteeio 4.12.6

2 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
graviteeio/am-gateway:4.12.607b7f6dc267a
httpclient@4.5.12
4.5.13
graviteeio/am-management-api:4.12.6a8eb04ee0c70
httpclient@4.5.12
4.5.13

Open the chart page →

2,088
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
httpclient@4.5.6
4.5.13

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
httpclient@4.5.2
4.5.13

Open the chart page →

4,679
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
httpclient@4.5.10
4.5.13

Open the chart page →

17,284
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
glarad/mc-service-registry:latest7b02b9e7f1ef
httpclient@4.5.3
4.5.13

Open the chart page →

6,929
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
httpclient@4.5.2
4.5.13

Open the chart page →

5,772
glowrootnovum-rgi-charts1.0.101 of 2See more

glowroot novum-rgi-charts 1.0.10

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
httpclient@4.5.11
4.5.13

Open the chart page →

2,308
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
httpclient@4.5.2
4.5.13

Open the chart page →

1,916
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
httpclient@4.5.10
4.5.13

Open the chart page →

31,844
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
httpclient@4.5.6
4.5.13

Open the chart page →

4,621
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
httpclient@4.5.10
4.5.13

Open the chart page →

6,045
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
httpclient@4.3.5
4.5.13

Open the chart page →

4,983
seldon-coreseldon0.2.71 of 3See more

seldon-core seldon 0.2.7

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
httpclient@4.5.6
4.5.13

Open the chart page →

13,798

Container images carrying it

217 by charts deploying them

A fixed version is listed for 28 of the 28 affected packages.

Container imageDigestPackageFixed inUsed by
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13
7
bde2020/hive:2.3.2-postgresql-metastore620267768985
httpclient@4.2.5
4.5.13
4
gradiant/hbase-base:2.0.1a1ee6de94c04
httpclient@4.5.3
4.5.13
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
httpclient@4.5.10
4.5.13
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
httpclient@4.5.10
4.5.13
3
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient@4.5.5
4.5.13
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
httpclient@4.5.10
4.5.13
2
apache/druid:37.0.00116fb802786
httpclient@4.5.2
4.5.13
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
httpclient@4.5.5
4.5.13
2
danisla/hadoop:2.9.0255ba2dd739b
httpclient@4.5.2
4.5.13
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
httpclient@4.5.2
4.5.13
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
httpclient@4.5.12
4.5.13
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
httpclient@4.2.5
4.5.13
2
gradiant/opentsdb:2.4.0c33d53913869
httpclient@4.3.1
4.5.13
2
gradiant/spark:2.4.4-python-alpine97657d56e927
httpclient@4.5.6
4.5.13
2
library/elasticsearch:7.17.35e6ac15bf6a5
httpclient@4.5.10
4.5.13
2
mbentley/omada-controller:4.3f4e682274bed
httpclient@4.5.7
4.5.13
2
nacos/nacos-server:v2.1.0dcf04549c6d7
httpclient@4.5.12
4.5.13
2
opensearchproject/opensearch:2.1.04254021a8c71
httpclient@4.5.10
4.5.13
2
rodolpheche/wiremock:2.26.03be08a386092
httpclient@4.5.6
4.5.13
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
httpclient@4.5.10
4.5.13
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
httpclient@4.5.10
4.5.13
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
httpclient@4.5.2
4.5.13
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
httpclient@4.5.8
4.5.13
1
andrianrf/bpjstk-service:latest46abe878d9d8
httpclient@4.5.12
4.5.13
1
apache/druid:29.0.10cef139b6bf1
httpclient@4.5.2
4.5.13
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient@4.5.6
4.5.13
1
apacheignite/ignite:2.7.0d7deab68b8fa
httpclient@4.5.1
4.5.13
1
apache/nifi-registry:1.14.0090b7f87ec7f
httpclient@4.5.6
4.5.13
1
apache/nifi-registry:0.8.0974efa2f21da
httpclient@4.5.6
4.5.13
1
apachepulsar/pulsar:2.6.14db6ff0b4045
httpclient@4.5.5
4.5.13
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
httpclient@4.5.7
4.5.13
1
apache/skywalking-ui:8.1.067d50e4deff4
httpclient@4.5.3
4.5.13
1
apache/skywalking-ui:8.9.180530f0308a5
httpclient@4.5.3
4.5.13
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec
1
assistiot/authorization_svr:latestdb9361dad79b
httpclient@4.5.9
4.5.13
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
httpclient@4.5.3
4.5.13
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
httpclient@4.5.10
4.5.13
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
httpclient@4.5.10
4.5.13
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
httpclient@4.5.6
4.5.13
1
atlassian/confluence-server:7.10.03b9222ab32ef
httpclient@4.5.10
4.5.13
1
atlassian/jira-software:8.14.037bc46cbec1a
httpclient@4.5.10
4.5.13
1
atomix/atomix:3.1.127738ff4f5c63
httpclient@4.5.2
4.5.13
1
bivas/presto:0.19605545994f806
httpclient@4.5.2
4.5.13
1
choerodon/event-store-service:0.8.03c94c97f6f69
httpclient@4.5.3
4.5.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.