StackRadar

CVE-2020-13956

Medium

Advisory

Published 3 Jun 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.090
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
190
of 17,781 indexed, latest versions
Container images
217
deployed by those charts
Fix available
28 of 28
affected packages

Cross-site scripting in Apache HttpClient

Carried by container images the latest versions of 190 of 17,781 indexed charts deploy, on 217 images.

Affected packageAffected versionsFixed inImages
httpclientmaven4.0.1, 4.0.2, 4.2.5, 4.2.6+19 more4.5.13217
aopalliancerpm1.0-20.module+el8.3.0+6804+157bd82e0:1.0-20.module+el8.6.0+13337+afcb49ec5
apache-commons-clirpm1.4-7.module+el8.3.0+6804+157bd82e0:1.4-7.module+el8.6.0+13337+afcb49ec5
apache-commons-codecrpm1.13-3.module+el8.3.0+6804+157bd82e0:1.13-3.module+el8.6.0+13337+afcb49ec5
apache-commons-iorpm1:2.6-6.module+el8.3.0+6804+157bd82e1:2.6-6.module+el8.6.0+13337+afcb49ec5
apache-commons-lang3rpm3.9-4.module+el8.3.0+6804+157bd82e0:3.9-4.module+el8.6.0+13337+afcb49ec5
atinjectrpm1-31.20100611svn86.module+el8.3.0+6804+157bd82e0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec5
cdi-apirpm2.0.1-3.module+el8.3.0+6804+157bd82e0:2.0.1-3.module+el8.6.0+13337+afcb49ec5
geronimo-annotationrpm1.0-26.module+el8.3.0+6804+157bd82e0:1.0-26.module+el8.6.0+13337+afcb49ec5
google-guicerpm4.2.2-4.module+el8.3.0+6804+157bd82e0:4.2.2-4.module+el8.6.0+13337+afcb49ec5
guavarpm28.1-3.module+el8.3.0+6804+157bd82e0:28.1-3.module+el8.6.0+13337+afcb49ec5
httpcomponents-clientrpm4.5.10-3.module+el8.3.0+6804+157bd82e0:4.5.10-4.module+el8.6.0+13337+afcb49ec5
httpcomponents-corerpm4.4.12-3.module+el8.3.0+6804+157bd82e0:4.4.12-3.module+el8.6.0+13337+afcb49ec5
jansirpm1.18-4.module+el8.3.0+6804+157bd82e0:1.18-4.module+el8.6.0+13337+afcb49ec5
jsouprpm1.12.1-3.module+el8.3.0+6804+157bd82e0:1.12.1-3.module+el8.6.0+13337+afcb49ec5
jsr-305rpm0-0.25.20130910svn.module+el8.3.0+6804+157bd82e0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec5
mavenrpm1:3.6.2-6.module+el8.4.0+9250+1786af371:3.6.2-7.module+el8.6.0+13337+afcb49ec5
maven-resolverrpm1.4.1-3.module+el8.3.0+6804+157bd82e0:1.4.1-3.module+el8.6.0+13337+afcb49ec5
maven-shared-utilsrpm3.2.1-0.4.module+el8.3.0+6804+157bd82e0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec5
maven-wagonrpm3.3.4-2.module+el8.3.0+6804+157bd82e0:3.3.4-2.module+el8.6.0+13337+afcb49ec5
plexus-cipherrpm1.7-17.module+el8.3.0+6804+157bd82e0:1.7-17.module+el8.6.0+13337+afcb49ec5
plexus-classworldsrpm2.6.0-4.module+el8.3.0+6804+157bd82e0:2.6.0-4.module+el8.6.0+13337+afcb49ec5
plexus-containersrpm2.1.0-2.module+el8.3.0+6804+157bd82e0:2.1.0-2.module+el8.6.0+13337+afcb49ec5
plexus-interpolationrpm1.26-3.module+el8.3.0+6804+157bd82e0:1.26-3.module+el8.6.0+13337+afcb49ec5
plexus-sec-dispatcherrpm1.4-29.module+el8.3.0+6804+157bd82e0:1.4-29.module+el8.6.0+13337+afcb49ec5
plexus-utilsrpm3.3.0-3.module+el8.3.0+6804+157bd82e0:3.3.0-3.module+el8.6.0+13337+afcb49ec5
sisurpm0.3.4-2.module+el8.3.0+6804+157bd82e0:0.3.4-2.module+el8.6.0+13337+afcb49ec5
slf4jrpm1.7.28-3.module+el8.3.0+6804+157bd82e0:1.7.28-3.module+el8.6.0+13337+afcb49ec5
OSV records
GHSA-7r82-7xv7-xcpjRHSA-2022:1860

Charts affected

190 by stars
ChartLatestAffected imagesRadar Score
signserver-cesignserverOfficialVerified publisher2.3.51 of 1See more

signserver-ce signserver 2.3.5

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
keyfactor/signserver-ce:7.3.2798fbbe00283
httpclient@4.5.5
4.5.13

Open the chart page →

2,406
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
httpclient@4.5.4
4.5.13

Open the chart page →

8,063
snowplowt3n0.0.11 of 1See more

snowplow t3n 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
httpclient@4.5.12
4.5.13

Open the chart page →

2,269
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
httpclient@4.5.12
4.5.13

Open the chart page →

15,970
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.1_local75f00caa6f3f
httpclient@4.5.2
4.5.13

Open the chart page →

4,777
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
httpclient@4.5.2
4.5.13

Open the chart page →

6,486
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
httpclient@4.5.2
4.5.13

Open the chart page →

5,489
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
httpclient@4.3-beta1
4.5.13

Open the chart page →

3,437
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
httpclient@4.5.7
4.5.13

Open the chart page →

11,553
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
httpclient@4.5.10
4.5.13

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
httpclient@4.5.10
4.5.13

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
httpclient@4.5.12
4.5.13

Open the chart page →

8,866
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
assistiot/authorization_svr:latestdb9361dad79b
httpclient@4.5.9
4.5.13

Open the chart page →

5,537
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
httpclient@4.5.6
4.5.13

Open the chart page →

7,936
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
httpclient@4.5.10
4.5.13

Open the chart page →

5,806
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
httpclient@4.5.12
4.5.13
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
httpclient@4.5.12
4.5.13

Open the chart page →

88,335
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
httpclient@4.5.2
4.5.13

Open the chart page →

12,018
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
httpclient@4.5.3
4.5.13

Open the chart page →

9,808
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
httpclient@4.5.8
4.5.13

Open the chart page →

6,447
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
httpclient@4.2.5
4.5.13

Open the chart page →

5,078
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
httpclient@4.3.6
4.5.13

Open the chart page →

4,906
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
httpclient@4.5.6
4.5.13
gocd/gocd-server:v19.3.02da45cb09d57
httpclient@4.5.6
4.5.13

Open the chart page →

9,144
hazelcastcloudnativeapp1.3.11 of 1See more

hazelcast cloudnativeapp 1.3.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
hazelcast/hazelcast:3.11.2ca7d5589744f
httpclient@4.4.1
4.5.13

Open the chart page →

4,982
hazelcast-jetcloudnativeapp1.1.01 of 1See more

hazelcast-jet cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:3.0df495e64ea65
httpclient@4.4.1
4.5.13

Open the chart page →

5,326
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
httpclient@4.5.2
4.5.13

Open the chart page →

4,601
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
httpclient@4.5.2
4.5.13

Open the chart page →

7,226
prometheus-cloudwatch-exportercloudnativeapp0.4.51 of 1See more

prometheus-cloudwatch-exporter cloudnativeapp 0.4.5

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:cloudwatch_exporter-0.5.0923705b2ae77
httpclient@4.5.2
4.5.13

Open the chart page →

2,629
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
httpclient@4.5.3
4.5.13

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
httpclient@4.0.1
4.5.13

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
httpclient@4.5.6
4.5.13

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
httpclient@4.5.6
4.5.13

Open the chart page →

22,442
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
httpclient@4.5.12
4.5.13

Open the chart page →

29,555
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
httpclient@4.5.5
4.5.13
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
httpclient@4.5.5
4.5.13

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
httpclient@4.5.3
4.5.13
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
httpclient@4.5.3
4.5.13
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
httpclient@4.5.3
4.5.13
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
httpclient@4.5.3
4.5.13
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
httpclient@4.5.3
4.5.13
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
httpclient@4.5.3
4.5.13

Open the chart page →

58,857
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
httpclient@4.5.6
4.5.13

Open the chart page →

8,245
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
httpclient@4.5.6
4.5.13

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
httpclient@4.5.9
4.5.13

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
httpclient@4.5.9
4.5.13

Open the chart page →

4,592
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
httpclient@4.0.1
4.5.13

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
httpclient@4.5.9
4.5.13

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
httpclient@4.5.8
4.5.13

Open the chart page →

2,237
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
httpclient@4.5.10
4.5.13

Open the chart page →

11,482
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient@4.5.5
4.5.13

Open the chart page →

7,268
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
httpclient@4.5.10
4.5.13

Open the chart page →

10,564
shenyuerdeng2.4.212 of 2See more

shenyu erdeng 2.4.21

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
httpclient@4.5.10
4.5.13
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
httpclient@4.5.10
4.5.13

Open the chart page →

12,513
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
httpclient@4.5.8
4.5.13

Open the chart page →

2,021
apollofiware0.1.41 of 1See more

apollo fiware 0.1.4

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/apollo:0.0.1055330b1b60c1
httpclient@4.5.10
4.5.13

Open the chart page →

6,936
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec

Open the chart page →

8,528
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
httpclient@4.5.10
4.5.13

Open the chart page →

4,536
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
httpclient@4.5.10
4.5.13

Open the chart page →

11,835

Container images carrying it

217 by charts deploying them

A fixed version is listed for 28 of the 28 affected packages.

Container imageDigestPackageFixed inUsed by
ibmcom/microclimate-theia:lateste17bdccc5030
httpclient@4.0.2
4.5.13
1
jacobalberty/unifi:v7.1.664a3616625dda
httpclient@4.5.10
4.5.13
1
jacobalberty/unifi:5.10.19c409924e2463
httpclient@4.5.6
4.5.13
1
jenkinsci/jenkins:2.67a1f33f004659
httpclient@4.5.1
4.5.13
1
keyfactor/signserver-ce:7.3.2798fbbe00283
httpclient@4.5.5
4.5.13
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
httpclient@4.5.12
4.5.13
1
kyso/imagebox:latest68091eace89c
httpclient@4.5.1
4.5.13
1
ladeit/ladeit:latest962b665ffe82
httpclient@4.5.6
4.5.13
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
httpclient@4.5.12
4.5.13
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
httpclient@4.5.12
4.5.13
1
library/crate:4.7.0c7984a05e15b
httpclient@4.5.12
4.5.13
1
library/elasticsearch:7.17.0332c6d416808
httpclient@4.5.10
4.5.13
1
library/elasticsearch:7.17.1588c2ec10c7f2
httpclient@4.5.10
4.5.13
1
library/elasticsearch:7.17.8fdc73b3249c1
httpclient@4.5.10
4.5.13
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
httpclient@4.5.3
4.5.13
1
library/solr:8.7.0d124efd81fbb
httpclient@4.5.12
4.5.13
1
library/sonarqube:6.7.6-community0ae5169e3d0f
httpclient@4.3.6
4.5.13
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
httpclient@4.5.10
4.5.13
1
library/sonarqube:8.2-communitya246bc64207e
httpclient@4.5.2
4.5.13
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
httpclient@4.5.10
4.5.13
1
library/sonarqube:8.9-communityeb2f0be32efd
httpclient@4.5.10
4.5.13
1
library/storm:2.4.0bd5d420506d6
httpclient@4.5.6
4.5.13
1
lightbend/spark-history-server:2.4.00bedf37f428a
httpclient@4.5.6
4.5.13
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpclient@4.5.5
4.5.13
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
httpclient@4.5.11
4.5.13
1
metabase/metabase:v0.31.2ffb2dccacefc
httpclient@4.5.2
4.5.13
1
microcks/microcks:0.8.0e3a3e0c67b09
httpclient@4.5.2
4.5.13
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
httpclient@4.2.6
4.5.13
1
muluder/prograncontrollermcord:0.1.843b597a93da7
httpclient@4.3.5
4.5.13
1
nacos/nacos-server:1.4.1fe6e5688cdf3
httpclient@4.5
4.5.13
1
ncsapolyglot/converters-avconv:latestc44b22eb58bb
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-flac:latest072cf5bc6f99
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-gdal:latestf746049515c1
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-ghostscript:latestf350da56dd55
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-htmldoc:latest317dd9e56922
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-txt2html:latest30ee96508c0b
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
httpclient@4.3.1
4.5.13
1
ncsapolyglot/converters-zip:latestf889fe30e2c7
httpclient@4.3.1
4.5.13
1
ncsapolyglot/polyglot:2.4.097a8c01c076e
httpclient@4.3.1
4.5.13
1
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
httpclient@4.5.11
4.5.13
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
httpclient@4.5.3
4.5.13
1
omecproject/onos-progran:1.0.05715e5648aa0
httpclient@4.3.5
4.5.13
1
onosproject/onos:2.2.144914a8d4b3f
httpclient@4.5.1
4.5.13
1
opencord/ves-agent:1.0.04187e2a8c918
httpclient@4.5.6
4.5.13
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
httpclient@4.3-beta1
4.5.13
1
openkm/openkm-ce:6.3.113bc465a7461b
httpclient@4.0.1
4.5.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.