StackRadar

CVE-2020-13956

Medium

Advisory

Published 3 Jun 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.090
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
190
of 17,781 indexed, latest versions
Container images
217
deployed by those charts
Fix available
28 of 28
affected packages

Cross-site scripting in Apache HttpClient

Carried by container images the latest versions of 190 of 17,781 indexed charts deploy, on 217 images.

Affected packageAffected versionsFixed inImages
httpclientmaven4.0.1, 4.0.2, 4.2.5, 4.2.6+19 more4.5.13217
aopalliancerpm1.0-20.module+el8.3.0+6804+157bd82e0:1.0-20.module+el8.6.0+13337+afcb49ec5
apache-commons-clirpm1.4-7.module+el8.3.0+6804+157bd82e0:1.4-7.module+el8.6.0+13337+afcb49ec5
apache-commons-codecrpm1.13-3.module+el8.3.0+6804+157bd82e0:1.13-3.module+el8.6.0+13337+afcb49ec5
apache-commons-iorpm1:2.6-6.module+el8.3.0+6804+157bd82e1:2.6-6.module+el8.6.0+13337+afcb49ec5
apache-commons-lang3rpm3.9-4.module+el8.3.0+6804+157bd82e0:3.9-4.module+el8.6.0+13337+afcb49ec5
atinjectrpm1-31.20100611svn86.module+el8.3.0+6804+157bd82e0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec5
cdi-apirpm2.0.1-3.module+el8.3.0+6804+157bd82e0:2.0.1-3.module+el8.6.0+13337+afcb49ec5
geronimo-annotationrpm1.0-26.module+el8.3.0+6804+157bd82e0:1.0-26.module+el8.6.0+13337+afcb49ec5
google-guicerpm4.2.2-4.module+el8.3.0+6804+157bd82e0:4.2.2-4.module+el8.6.0+13337+afcb49ec5
guavarpm28.1-3.module+el8.3.0+6804+157bd82e0:28.1-3.module+el8.6.0+13337+afcb49ec5
httpcomponents-clientrpm4.5.10-3.module+el8.3.0+6804+157bd82e0:4.5.10-4.module+el8.6.0+13337+afcb49ec5
httpcomponents-corerpm4.4.12-3.module+el8.3.0+6804+157bd82e0:4.4.12-3.module+el8.6.0+13337+afcb49ec5
jansirpm1.18-4.module+el8.3.0+6804+157bd82e0:1.18-4.module+el8.6.0+13337+afcb49ec5
jsouprpm1.12.1-3.module+el8.3.0+6804+157bd82e0:1.12.1-3.module+el8.6.0+13337+afcb49ec5
jsr-305rpm0-0.25.20130910svn.module+el8.3.0+6804+157bd82e0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec5
mavenrpm1:3.6.2-6.module+el8.4.0+9250+1786af371:3.6.2-7.module+el8.6.0+13337+afcb49ec5
maven-resolverrpm1.4.1-3.module+el8.3.0+6804+157bd82e0:1.4.1-3.module+el8.6.0+13337+afcb49ec5
maven-shared-utilsrpm3.2.1-0.4.module+el8.3.0+6804+157bd82e0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec5
maven-wagonrpm3.3.4-2.module+el8.3.0+6804+157bd82e0:3.3.4-2.module+el8.6.0+13337+afcb49ec5
plexus-cipherrpm1.7-17.module+el8.3.0+6804+157bd82e0:1.7-17.module+el8.6.0+13337+afcb49ec5
plexus-classworldsrpm2.6.0-4.module+el8.3.0+6804+157bd82e0:2.6.0-4.module+el8.6.0+13337+afcb49ec5
plexus-containersrpm2.1.0-2.module+el8.3.0+6804+157bd82e0:2.1.0-2.module+el8.6.0+13337+afcb49ec5
plexus-interpolationrpm1.26-3.module+el8.3.0+6804+157bd82e0:1.26-3.module+el8.6.0+13337+afcb49ec5
plexus-sec-dispatcherrpm1.4-29.module+el8.3.0+6804+157bd82e0:1.4-29.module+el8.6.0+13337+afcb49ec5
plexus-utilsrpm3.3.0-3.module+el8.3.0+6804+157bd82e0:3.3.0-3.module+el8.6.0+13337+afcb49ec5
sisurpm0.3.4-2.module+el8.3.0+6804+157bd82e0:0.3.4-2.module+el8.6.0+13337+afcb49ec5
slf4jrpm1.7.28-3.module+el8.3.0+6804+157bd82e0:1.7.28-3.module+el8.6.0+13337+afcb49ec5
OSV records
GHSA-7r82-7xv7-xcpjRHSA-2022:1860

Charts affected

190 by stars
ChartLatestAffected imagesRadar Score
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
httpclient@4.5.2
4.5.13

Open the chart page →

2,421
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
httpclient@4.5.3
4.5.13

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
httpclient@4.3.5
4.5.13

Open the chart page →

88,546
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
httpclient@4.5.3
4.5.13

Open the chart page →

42,614
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
httpclient@4.5.1
4.5.13

Open the chart page →

12,927
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
httpclient@4.3.5
4.5.13

Open the chart page →

38,865
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
httpclient@4.5.6
4.5.13

Open the chart page →

6,350
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
httpclient@4.5.2
4.5.13
voltha/voltha-onos:5.1.8e038acb950d3
httpclient@4.5.6
4.5.13

Open the chart page →

41,044
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
andrianrf/bpjstk-service:latest46abe878d9d8
httpclient@4.5.12
4.5.13

Open the chart page →

34,671
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
httpclient@4.5.5
4.5.13

Open the chart page →

36,215
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
httpclient@4.5.2
4.5.13

Open the chart page →

9,606
prometheus-cloudwatch-exporterprometheus-worawutchan0.12.01 of 1See more

prometheus-cloudwatch-exporter prometheus-worawutchan 0.12.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:cloudwatch_exporter-0.8.0fc4b9b9f5e15
httpclient@4.5.9
4.5.13

Open the chart page →

2,831
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
httpclient@4.5.10
4.5.13

Open the chart page →

1,995
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
httpclient@4.5.5
4.5.13

Open the chart page →

3,642
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
httpclient@4.5.11
4.5.13
reportportal/service-authorization:5.7.09e73114dbd15
httpclient@4.5.11
4.5.13

Open the chart page →

25,737
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
httpclient@4.5.12
4.5.13

Open the chart page →

3,978
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
httpclient@4.5.6
4.5.13

Open the chart page →

8,098
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
httpclient@4.5.9
4.5.13

Open the chart page →

10,967
shenyushenyu-helm-chart-test2.4.272 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
httpclient@4.5.10
4.5.13
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
httpclient@4.5.10
4.5.13

Open the chart page →

12,513
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
httpclient@4.5.10
4.5.13

Open the chart page →

6,949
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
httpclient@4.5.2
4.5.13

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
httpclient@4.5.10
4.5.13

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
httpclient@4.5.10
4.5.13

Open the chart page →

13,079
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
httpclient@4.5.10
4.5.13

Open the chart page →

3,164
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
httpclient@4.5.10
4.5.13

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
httpclient@4.5.10
4.5.13

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
httpclient@4.3.6
4.5.13

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
httpclient@4.5.10
4.5.13

Open the chart page →

14,493
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
httpclient@4.5.12
4.5.13

Open the chart page →

13,767
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
httpclient@4.5.10
4.5.13

Open the chart page →

4,538
shenyutest-helm2.4.212 of 2See more

shenyu test-helm 2.4.21

2 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
httpclient@4.5.10
4.5.13
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
httpclient@4.5.10
4.5.13

Open the chart page →

12,513
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec

Open the chart page →

12,455
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
httpclient@4.4
4.5.13

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
httpclient@4.4
4.5.13

Open the chart page →

3,176
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
httpclient@4.5.2
4.5.13

Open the chart page →

5,460
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
httpclient@4.5.10
4.5.13

Open the chart page →

5,806
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
httpclient@4.5.11
4.5.13

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient@4.5.3
4.5.13

Open the chart page →

3,480

Container images carrying it

217 by charts deploying them

A fixed version is listed for 28 of the 28 affected packages.

Container imageDigestPackageFixed inUsed by
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
httpclient@4.3.5
4.5.13
1
openwhisk/invoker:1.0.0f5831ec85525
httpclient@4.5.5
4.5.13
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
httpclient@4.5.10
4.5.13
1
owasp/dependency-track:3.8.0efc65e702ee1
httpclient@4.5.9
4.5.13
1
pedrocesarti/jmeter-docker:3.314851f144f57
httpclient@4.5.3
4.5.13
1
penpotapp/exporter:2.2.15c835ffd87ab
httpclient@4.5.3
4.5.13
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
httpclient@4.5.2
4.5.13
1
prom/cloudwatch-exporter:cloudwatch_exporter-0.5.0923705b2ae77
httpclient@4.5.2
4.5.13
1
prom/cloudwatch-exporter:cloudwatch_exporter-0.8.0fc4b9b9f5e15
httpclient@4.5.9
4.5.13
1
raykrueger/riemann:0.2.14c8baf3de57bb
httpclient@4.5.3
4.5.13
1
refar/apm-api:v5.7.1241373fa2972
httpclient@4.5.12
4.5.13
1
refar/apm-operator-server:v5.7.1e5490f050f9f
httpclient@4.5.12
4.5.13
1
reportportal/service-api:5.7.29df41f8fb320
httpclient@4.5.11
4.5.13
1
reportportal/service-authorization:5.7.09e73114dbd15
httpclient@4.5.11
4.5.13
1
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
httpclient@4.5.3
4.5.13
1
robotshop/rs-shipping:latest89753ab48919
httpclient@4.5.12
4.5.13
1
rodolpheche/wiremock:2.27.22328a9fce2bf
httpclient@4.5.12
4.5.13
1
rundeck/rundeck:3.2.74d64fe56f767
httpclient@4.5.9
4.5.13
1
rundeck/rundeck:3.0.16b13e8059ad72
httpclient@4.0.1
4.5.13
1
seldonio/apife:0.2.7ba81b17f00eb
httpclient@4.5.6
4.5.13
1
seldonio/apife:0.3.1eea0d3f578ca
httpclient@4.5.6
4.5.13
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
httpclient@4.5.2
4.5.13
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
httpclient@4.0.1
4.5.13
1
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
httpclient@4.5.12
4.5.13
1
sslhep/hive-metastore:3.1.39e80af083079
httpclient@4.5.2
4.5.13
1
thehiveproject/cortex:3.1.7f4bc64fb8844
httpclient@4.5.10
4.5.13
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
httpclient@4.2.5
4.5.13
1
trinodb/trino:405ee80ab5eeab2
httpclient@4.5.12
4.5.13
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec
1
voltha/voltha-onos:5.1.8e038acb950d3
httpclient@4.5.6
4.5.13
1
vromero/activemq-artemis:2.16.0408d6a46b153
httpclient@4.5.2
4.5.13
1
wavefronthq/proxy:9.2d1064d28f6eb
httpclient@4.5.12
4.5.13
1
wistefan/mvf:lateste0887302b2d8
httpclient@4.5.2
4.5.13
1
woojoong/wowza:latestec230db19652
httpclient@4.5.3
4.5.13
1
xetusoss/archiva:v2.2.588f25242b9ee
httpclient@4.5.2
4.5.13
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
httpclient@4.5.3
4.5.13
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
httpclient@4.5.10
4.5.13
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
httpclient@4.3.6
4.5.13
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
httpclient@4.5.10
4.5.13
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
httpclient@4.5.10
4.5.13
1
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
httpclient@4.5.3
4.5.13
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
httpclient@4.5.3
4.5.13
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
httpclient@4.5.3
4.5.13
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
httpclient@4.5.3
4.5.13
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
httpclient@4.5.3
4.5.13
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
httpclient@4.5.3
4.5.13
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
httpclient@4.5.3
4.5.13
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
httpclient@4.5.12
4.5.13
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
httpclient@4.5.2
4.5.13
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
httpclient@4.5.12
4.5.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.