StackRadar

CVE-2020-13956

Medium

Advisory

Published 3 Jun 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.090
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
190
of 17,781 indexed, latest versions
Container images
217
deployed by those charts
Fix available
28 of 28
affected packages

Cross-site scripting in Apache HttpClient

Carried by container images the latest versions of 190 of 17,781 indexed charts deploy, on 217 images.

Affected packageAffected versionsFixed inImages
httpclientmaven4.0.1, 4.0.2, 4.2.5, 4.2.6+19 more4.5.13217
aopalliancerpm1.0-20.module+el8.3.0+6804+157bd82e0:1.0-20.module+el8.6.0+13337+afcb49ec5
apache-commons-clirpm1.4-7.module+el8.3.0+6804+157bd82e0:1.4-7.module+el8.6.0+13337+afcb49ec5
apache-commons-codecrpm1.13-3.module+el8.3.0+6804+157bd82e0:1.13-3.module+el8.6.0+13337+afcb49ec5
apache-commons-iorpm1:2.6-6.module+el8.3.0+6804+157bd82e1:2.6-6.module+el8.6.0+13337+afcb49ec5
apache-commons-lang3rpm3.9-4.module+el8.3.0+6804+157bd82e0:3.9-4.module+el8.6.0+13337+afcb49ec5
atinjectrpm1-31.20100611svn86.module+el8.3.0+6804+157bd82e0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec5
cdi-apirpm2.0.1-3.module+el8.3.0+6804+157bd82e0:2.0.1-3.module+el8.6.0+13337+afcb49ec5
geronimo-annotationrpm1.0-26.module+el8.3.0+6804+157bd82e0:1.0-26.module+el8.6.0+13337+afcb49ec5
google-guicerpm4.2.2-4.module+el8.3.0+6804+157bd82e0:4.2.2-4.module+el8.6.0+13337+afcb49ec5
guavarpm28.1-3.module+el8.3.0+6804+157bd82e0:28.1-3.module+el8.6.0+13337+afcb49ec5
httpcomponents-clientrpm4.5.10-3.module+el8.3.0+6804+157bd82e0:4.5.10-4.module+el8.6.0+13337+afcb49ec5
httpcomponents-corerpm4.4.12-3.module+el8.3.0+6804+157bd82e0:4.4.12-3.module+el8.6.0+13337+afcb49ec5
jansirpm1.18-4.module+el8.3.0+6804+157bd82e0:1.18-4.module+el8.6.0+13337+afcb49ec5
jsouprpm1.12.1-3.module+el8.3.0+6804+157bd82e0:1.12.1-3.module+el8.6.0+13337+afcb49ec5
jsr-305rpm0-0.25.20130910svn.module+el8.3.0+6804+157bd82e0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec5
mavenrpm1:3.6.2-6.module+el8.4.0+9250+1786af371:3.6.2-7.module+el8.6.0+13337+afcb49ec5
maven-resolverrpm1.4.1-3.module+el8.3.0+6804+157bd82e0:1.4.1-3.module+el8.6.0+13337+afcb49ec5
maven-shared-utilsrpm3.2.1-0.4.module+el8.3.0+6804+157bd82e0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec5
maven-wagonrpm3.3.4-2.module+el8.3.0+6804+157bd82e0:3.3.4-2.module+el8.6.0+13337+afcb49ec5
plexus-cipherrpm1.7-17.module+el8.3.0+6804+157bd82e0:1.7-17.module+el8.6.0+13337+afcb49ec5
plexus-classworldsrpm2.6.0-4.module+el8.3.0+6804+157bd82e0:2.6.0-4.module+el8.6.0+13337+afcb49ec5
plexus-containersrpm2.1.0-2.module+el8.3.0+6804+157bd82e0:2.1.0-2.module+el8.6.0+13337+afcb49ec5
plexus-interpolationrpm1.26-3.module+el8.3.0+6804+157bd82e0:1.26-3.module+el8.6.0+13337+afcb49ec5
plexus-sec-dispatcherrpm1.4-29.module+el8.3.0+6804+157bd82e0:1.4-29.module+el8.6.0+13337+afcb49ec5
plexus-utilsrpm3.3.0-3.module+el8.3.0+6804+157bd82e0:3.3.0-3.module+el8.6.0+13337+afcb49ec5
sisurpm0.3.4-2.module+el8.3.0+6804+157bd82e0:0.3.4-2.module+el8.6.0+13337+afcb49ec5
slf4jrpm1.7.28-3.module+el8.3.0+6804+157bd82e0:1.7.28-3.module+el8.6.0+13337+afcb49ec5
OSV records
GHSA-7r82-7xv7-xcpjRHSA-2022:1860

Charts affected

190 by stars
ChartLatestAffected imagesRadar Score
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
httpclient@4.5.5
4.5.13

Open the chart page →

2,406
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
httpclient@4.5.4
4.5.13

Open the chart page →

8,063
snowplowt3n0.0.11 of 1See more

snowplow t3n 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
httpclient@4.5.12
4.5.13

Open the chart page →

2,269
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
httpclient@4.5.12
4.5.13

Open the chart page →

15,970
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.1_local75f00caa6f3f
httpclient@4.5.2
4.5.13

Open the chart page →

4,777
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
httpclient@4.5.2
4.5.13

Open the chart page →

6,486
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
httpclient@4.5.2
4.5.13

Open the chart page →

5,489
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
httpclient@4.3-beta1
4.5.13

Open the chart page →

3,437
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
httpclient@4.5.7
4.5.13

Open the chart page →

11,553
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
httpclient@4.5.10
4.5.13

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
httpclient@4.5.10
4.5.13

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
httpclient@4.5.12
4.5.13

Open the chart page →

8,866
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
assistiot/authorization_svr:latestdb9361dad79b
httpclient@4.5.9
4.5.13

Open the chart page →

5,537
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
httpclient@4.5.6
4.5.13

Open the chart page →

7,936
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
httpclient@4.5.10
4.5.13

Open the chart page →

5,806
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
httpclient@4.5.12
4.5.13

Open the chart page →

88,335
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
httpclient@4.5.2
4.5.13

Open the chart page →

12,018
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
httpclient@4.5.3
4.5.13

Open the chart page →

9,808
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
httpclient@4.5.8
4.5.13

Open the chart page →

6,447
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
httpclient@4.2.5
4.5.13

Open the chart page →

5,078
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
httpclient@4.3.6
4.5.13

Open the chart page →

4,906
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
httpclient@4.5.6
4.5.13
gocd/gocd-server:v19.3.02da45cb09d57
httpclient@4.5.6
4.5.13

Open the chart page →

9,144
hazelcastcloudnativeapp1.3.11 of 1See more

hazelcast cloudnativeapp 1.3.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
hazelcast/hazelcast:3.11.2ca7d5589744f
httpclient@4.4.1
4.5.13

Open the chart page →

4,982
hazelcast-jetcloudnativeapp1.1.01 of 1See more

hazelcast-jet cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:3.0df495e64ea65
httpclient@4.4.1
4.5.13

Open the chart page →

5,326
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
httpclient@4.5.2
4.5.13

Open the chart page →

4,601
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
httpclient@4.5.2
4.5.13

Open the chart page →

7,226
prometheus-cloudwatch-exportercloudnativeapp0.4.51 of 1See more

prometheus-cloudwatch-exporter cloudnativeapp 0.4.5

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:cloudwatch_exporter-0.5.0923705b2ae77
httpclient@4.5.2
4.5.13

Open the chart page →

2,629
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
httpclient@4.5.3
4.5.13

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
httpclient@4.0.1
4.5.13

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
httpclient@4.5.6
4.5.13

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
httpclient@4.5.6
4.5.13

Open the chart page →

22,442
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
httpclient@4.5.12
4.5.13

Open the chart page →

29,555
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
httpclient@4.5.5
4.5.13
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
httpclient@4.5.5
4.5.13

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
httpclient@4.5.3
4.5.13
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
httpclient@4.5.3
4.5.13
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
httpclient@4.5.3
4.5.13
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
httpclient@4.5.3
4.5.13
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpclient@4.5.3
4.5.13
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
httpclient@4.5.3
4.5.13

Open the chart page →

58,857
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
httpclient@4.5.6
4.5.13

Open the chart page →

8,245
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
httpclient@4.5.6
4.5.13

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
httpclient@4.5.9
4.5.13

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
httpclient@4.5.9
4.5.13

Open the chart page →

4,592
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
httpclient@4.0.1
4.5.13

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
httpclient@4.5.9
4.5.13

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
httpclient@4.5.8
4.5.13

Open the chart page →

2,237
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
httpclient@4.5.10
4.5.13

Open the chart page →

11,482
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient@4.5.5
4.5.13

Open the chart page →

7,268
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
httpclient@4.5.10
4.5.13

Open the chart page →

10,564
shenyuerdeng2.4.212 of 2See more

shenyu erdeng 2.4.21

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
httpclient@4.5.10
4.5.13
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
httpclient@4.5.10
4.5.13

Open the chart page →

12,513
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
httpclient@4.5.8
4.5.13

Open the chart page →

2,021
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
httpclient@4.5.10
4.5.13

Open the chart page →

6,936
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec

Open the chart page →

8,528
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient@4.5.10
4.5.13

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
httpclient@4.5.10
4.5.13

Open the chart page →

11,835

Container images carrying it

217 by charts deploying them

A fixed version is listed for 28 of the 28 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
httpclient@4.5.3
4.5.13
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
httpclient@4.5.3
4.5.13
1
confluentinc/cp-kafka:5.4.01bbda887bc53
httpclient@4.5.9
4.5.13
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
httpclient@4.5.2
4.5.13
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
httpclient@4.5.3
4.5.13
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
httpclient@4.5.3
4.5.13
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpclient@4.5.3
4.5.13
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
httpclient@4.5.3
4.5.13
1
craigwillis/c2metadata-bd:latestae317d7e4724
httpclient@4.5.3
4.5.13
1
datappeal/hive-metastore:lateste38c085a3567
httpclient@4.5.2
4.5.13
1
dbanda/livy:0.80ca125e68e53
httpclient@4.5.2
4.5.13
1
dbanda/spark:2.4.6d0e6367876ae
httpclient@4.5.2
4.5.13
1
deltaio/delta-sharing-server:0.2.08b75118187c5
httpclient@4.5.2
4.5.13
1
dniel/api-posts:master45a667852f2a
httpclient@4.5.9
4.5.13
1
dniel/forwardauth:latestf67129ea1c64
httpclient@4.5.9
4.5.13
1
dremio/dremio-oss:24.1.080ed2e3b7c43
httpclient@4.5.2
4.5.13
1
drpcorg/dshackle:0.54.08858fae1859d
httpclient@4.5.8
4.5.13
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
httpclient@4.5.6
4.5.13
1
emcniece/dockeryourxyzzy:404eccbccc15c
httpclient@4.5.5
4.5.13
1
emeraldpay/dshackle:0.14.0126f0ae0b388
httpclient@4.5.8
4.5.13
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
httpclient@4.5.8
4.5.13
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
httpclient@4.5.10
4.5.13
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
httpclient@4.5.12
4.5.13
1
fiware/mintaka:0.7.092a3c5cf43c0
httpclient@4.5.10
4.5.13
1
fiware/mintaka:latestefc6793388cc
httpclient@4.5.10
4.5.13
1
folioci/edge-patron:latest682b852e056d
httpclient@4.5.3
4.5.13
1
fonoster/routr:1.0.0-rc52ca65af17cbc
httpclient@4.3.5
4.5.13
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
httpclient@4.5.12
4.5.13
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
httpclient@4.5.12
4.5.13
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
httpclient@4.5.12
4.5.13
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
httpclient@4.5.12
4.5.13
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
httpclient@4.5.12
4.5.13
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
httpclient@4.5.12
4.5.13
1
glarad/mc-service-registry:latest7b02b9e7f1ef
httpclient@4.5.3
4.5.13
1
gluufederation/opendj:4.3.0_011a1128b28b95
httpclient@4.5.6
4.5.13
1
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
httpclient@4.5.6
4.5.13
1
gocd/gocd-server:v19.3.02da45cb09d57
httpclient@4.5.6
4.5.13
1
gradiant/hdfs:3.2.2e3bf364fe713
httpclient@4.5.5
4.5.13
1
graviteeio/am-gateway:4.12.607b7f6dc267a
httpclient@4.5.12
4.5.13
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
httpclient@4.5.12
4.5.13
1
graylog2/server:2.4.3-38ff28c66e6c1
httpclient@4.5.4
4.5.13
1
gridgain/community:8.9.11d32d182a0e6a
httpclient@4.5.2
4.5.13
1
hazelcast/hazelcast:3.11.2ca7d5589744f
httpclient@4.4.1
4.5.13
1
hazelcast/hazelcast-jet:3.0df495e64ea65
httpclient@4.4.1
4.5.13
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
httpclient@4.5.2
4.5.13
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
httpclient@4.5.3
4.5.13
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
httpclient@4.3.6
4.5.13
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
httpclient@4.5.6
4.5.13
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
httpclient@4.0.2
4.5.13
1
ibmcom/microclimate-portal:latested5505e5c7ec
httpclient@4.5.3
4.5.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.