StackRadar

CVE-2020-13956

Medium

Advisory

Published 3 Jun 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.090
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
190
of 17,781 indexed, latest versions
Container images
217
deployed by those charts
Fix available
28 of 28
affected packages

Cross-site scripting in Apache HttpClient

Carried by container images the latest versions of 190 of 17,781 indexed charts deploy, on 217 images.

Affected packageAffected versionsFixed inImages
httpclientmaven4.0.1, 4.0.2, 4.2.5, 4.2.6+19 more4.5.13217
aopalliancerpm1.0-20.module+el8.3.0+6804+157bd82e0:1.0-20.module+el8.6.0+13337+afcb49ec5
apache-commons-clirpm1.4-7.module+el8.3.0+6804+157bd82e0:1.4-7.module+el8.6.0+13337+afcb49ec5
apache-commons-codecrpm1.13-3.module+el8.3.0+6804+157bd82e0:1.13-3.module+el8.6.0+13337+afcb49ec5
apache-commons-iorpm1:2.6-6.module+el8.3.0+6804+157bd82e1:2.6-6.module+el8.6.0+13337+afcb49ec5
apache-commons-lang3rpm3.9-4.module+el8.3.0+6804+157bd82e0:3.9-4.module+el8.6.0+13337+afcb49ec5
atinjectrpm1-31.20100611svn86.module+el8.3.0+6804+157bd82e0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec5
cdi-apirpm2.0.1-3.module+el8.3.0+6804+157bd82e0:2.0.1-3.module+el8.6.0+13337+afcb49ec5
geronimo-annotationrpm1.0-26.module+el8.3.0+6804+157bd82e0:1.0-26.module+el8.6.0+13337+afcb49ec5
google-guicerpm4.2.2-4.module+el8.3.0+6804+157bd82e0:4.2.2-4.module+el8.6.0+13337+afcb49ec5
guavarpm28.1-3.module+el8.3.0+6804+157bd82e0:28.1-3.module+el8.6.0+13337+afcb49ec5
httpcomponents-clientrpm4.5.10-3.module+el8.3.0+6804+157bd82e0:4.5.10-4.module+el8.6.0+13337+afcb49ec5
httpcomponents-corerpm4.4.12-3.module+el8.3.0+6804+157bd82e0:4.4.12-3.module+el8.6.0+13337+afcb49ec5
jansirpm1.18-4.module+el8.3.0+6804+157bd82e0:1.18-4.module+el8.6.0+13337+afcb49ec5
jsouprpm1.12.1-3.module+el8.3.0+6804+157bd82e0:1.12.1-3.module+el8.6.0+13337+afcb49ec5
jsr-305rpm0-0.25.20130910svn.module+el8.3.0+6804+157bd82e0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec5
mavenrpm1:3.6.2-6.module+el8.4.0+9250+1786af371:3.6.2-7.module+el8.6.0+13337+afcb49ec5
maven-resolverrpm1.4.1-3.module+el8.3.0+6804+157bd82e0:1.4.1-3.module+el8.6.0+13337+afcb49ec5
maven-shared-utilsrpm3.2.1-0.4.module+el8.3.0+6804+157bd82e0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec5
maven-wagonrpm3.3.4-2.module+el8.3.0+6804+157bd82e0:3.3.4-2.module+el8.6.0+13337+afcb49ec5
plexus-cipherrpm1.7-17.module+el8.3.0+6804+157bd82e0:1.7-17.module+el8.6.0+13337+afcb49ec5
plexus-classworldsrpm2.6.0-4.module+el8.3.0+6804+157bd82e0:2.6.0-4.module+el8.6.0+13337+afcb49ec5
plexus-containersrpm2.1.0-2.module+el8.3.0+6804+157bd82e0:2.1.0-2.module+el8.6.0+13337+afcb49ec5
plexus-interpolationrpm1.26-3.module+el8.3.0+6804+157bd82e0:1.26-3.module+el8.6.0+13337+afcb49ec5
plexus-sec-dispatcherrpm1.4-29.module+el8.3.0+6804+157bd82e0:1.4-29.module+el8.6.0+13337+afcb49ec5
plexus-utilsrpm3.3.0-3.module+el8.3.0+6804+157bd82e0:3.3.0-3.module+el8.6.0+13337+afcb49ec5
sisurpm0.3.4-2.module+el8.3.0+6804+157bd82e0:0.3.4-2.module+el8.6.0+13337+afcb49ec5
slf4jrpm1.7.28-3.module+el8.3.0+6804+157bd82e0:1.7.28-3.module+el8.6.0+13337+afcb49ec5
OSV records
GHSA-7r82-7xv7-xcpjRHSA-2022:1860

Charts affected

190 by stars
ChartLatestAffected imagesRadar Score
mintakafiware0.4.71 of 1See more

mintaka fiware 0.4.7

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
fiware/mintaka:latestefc6793388cc
httpclient@4.5.10
4.5.13

Open the chart page →

7,019
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
httpclient@4.5.10
4.5.13

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
httpclient@4.5.10
4.5.13

Open the chart page →

55,600
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
httpclient@4.5.10
4.5.13

Open the chart page →

7,087
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
httpclient@4.5.3
4.5.13

Open the chart page →

24,296
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
httpclient@4.5.3
4.5.13

Open the chart page →

905
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
httpclient@4.5.12
4.5.13

Open the chart page →

19,215
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
httpclient@4.0.1
4.5.13

Open the chart page →

27,949
pretend-youre-xyzzygeek-cookbookVerified publisher3.4.21 of 1See more

pretend-youre-xyzzy geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
emcniece/dockeryourxyzzy:404eccbccc15c
httpclient@4.5.5
4.5.13

Open the chart page →

581
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.1588c2ec10c7f2
httpclient@4.5.10
4.5.13

Open the chart page →

34,754
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
httpclient@4.5.6
4.5.13

Open the chart page →

3,064
hdfsgradiant-bigdataVerified publisher0.1.101 of 2See more

hdfs gradiant-bigdata 0.1.10

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13

Open the chart page →

7,073
hivegradiant-bigdataVerified publisher0.1.63 of 5See more

hive gradiant-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
httpclient@4.2.5
4.5.13
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
httpclient@4.2.5
4.5.13

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
httpclient@4.2.5
4.5.13

Open the chart page →

6,882
opentsdbgradiant-bigdataVerified publisher0.1.73 of 6See more

opentsdb gradiant-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
httpclient@4.5.3
4.5.13
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13
gradiant/opentsdb:2.4.0c33d53913869
httpclient@4.3.1
4.5.13

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
httpclient@4.5.6
4.5.13

Open the chart page →

6,147
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient@4.5.6
4.5.13

Open the chart page →

4,556
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
httpclient@4.5.2
4.5.13

Open the chart page →

6,362
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
httpclient@4.5.12
4.5.13

Open the chart page →

3,978
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
httpclient@4.5.6
4.5.13

Open the chart page →

2,140
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
httpclient@4.5.2
4.5.13

Open the chart page →

8,541
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apache/skywalking-ui:8.9.180530f0308a5
httpclient@4.5.3
4.5.13

Open the chart page →

20,650
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
httpclient@4.5.2
4.5.13

Open the chart page →

7,144
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
httpclient@4.5.2
4.5.13

Open the chart page →

7,862
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
httpclient@4.5.2
4.5.13
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
httpclient@4.5.3
4.5.13

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
httpclient@4.5.6
4.5.13

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
httpclient@4.0.2
4.5.13
ibmcom/microclimate-portal:latested5505e5c7ec
httpclient@4.5.3
4.5.13
ibmcom/microclimate-theia:lateste17bdccc5030
httpclient@4.0.2
4.5.13

Open the chart page →

57,669
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
httpclient@4.3.6
4.5.13

Open the chart page →

19,295
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
httpclient@4.5.2
4.5.13

Open the chart page →

37,671
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
httpclient@4.5.2
4.5.13

Open the chart page →

6,174
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
thehiveproject/cortex:3.1.7f4bc64fb8844
httpclient@4.5.10
4.5.13

Open the chart page →

6,122
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
httpclient@4.5.1
4.5.13

Open the chart page →

10,682
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
httpclient@4.5.12
4.5.13

Open the chart page →

12,856
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient@4.5.5
4.5.13

Open the chart page →

7,268
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
httpclient@4.5.12
4.5.13

Open the chart page →

8,884
tapm-componentkubebb5.7.12 of 3See more

tapm-component kubebb 5.7.1

2 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
httpclient@4.5.12
4.5.13
refar/apm-operator-server:v5.7.1e5490f050f9f
httpclient@4.5.12
4.5.13

Open the chart page →

10,264
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
httpclient@4.5.10
4.5.13

Open the chart page →

2,273
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
httpclient@4.5
4.5.13

Open the chart page →

4,153
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
httpclient@4.5.3
4.5.13

Open the chart page →

16,877
imageboxkyso1.0.01 of 1See more

imagebox kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
kyso/imagebox:latest68091eace89c
httpclient@4.5.1
4.5.13

Open the chart page →

3,833
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
httpclient@4.5.6
4.5.13

Open the chart page →

26,356
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
httpclient@4.5.12
4.5.13

Open the chart page →

2,427
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
httpclient@4.5.8
4.5.13

Open the chart page →

7,929
lavandaluiscajl0.0.1342 of 5See more

lavanda luiscajl 0.0.134

2 of the 5 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
httpclient@4.5.12
4.5.13
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
httpclient@4.5.12
4.5.13

Open the chart page →

18,248
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
httpclient@4.5.5
4.5.13

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
httpclient@4.2.6
4.5.13

Open the chart page →

43,341
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec

Open the chart page →

9,149
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
httpclient@4.5.10
4.5.13

Open the chart page →

9,300
polyglotncsaVerified publisher0.1.114 of 18See more

polyglot ncsa 0.1.1

14 of the 18 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
httpclient@4.5.3
4.5.13
ncsapolyglot/converters-avconv:latestc44b22eb58bb
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-flac:latest072cf5bc6f99
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-gdal:latestf746049515c1
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-ghostscript:latestf350da56dd55
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-htmldoc:latest317dd9e56922
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-txt2html:latest30ee96508c0b
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
httpclient@4.3.1
4.5.13
ncsapolyglot/converters-zip:latestf889fe30e2c7
httpclient@4.3.1
4.5.13
ncsapolyglot/polyglot:2.4.097a8c01c076e
httpclient@4.3.1
4.5.13

Open the chart page →

55,726
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2020-13956.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
httpclient@4.5.9
4.5.13

Open the chart page →

3,633

Container images carrying it

217 by charts deploying them

A fixed version is listed for 28 of the 28 affected packages.

Container imageDigestPackageFixed inUsed by
gradiant/hdfs:2.7.73b28784ba41f
httpclient@4.2.5
4.5.13
7
bde2020/hive:2.3.2-postgresql-metastore620267768985
httpclient@4.2.5
4.5.13
4
gradiant/hbase-base:2.0.1a1ee6de94c04
httpclient@4.5.3
4.5.13
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
httpclient@4.5.10
4.5.13
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
httpclient@4.5.10
4.5.13
3
jacobalberty/unifi:v10.0.162896c0ab82d33
httpclient@4.5.5
4.5.13
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
httpclient@4.5.10
4.5.13
2
apache/druid:37.0.00116fb802786
httpclient@4.5.2
4.5.13
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
httpclient@4.5.5
4.5.13
2
danisla/hadoop:2.9.0255ba2dd739b
httpclient@4.5.2
4.5.13
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
httpclient@4.5.2
4.5.13
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
httpclient@4.5.12
4.5.13
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
httpclient@4.5.12
4.5.13
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
httpclient@4.2.5
4.5.13
2
gradiant/opentsdb:2.4.0c33d53913869
httpclient@4.3.1
4.5.13
2
gradiant/spark:2.4.4-python-alpine97657d56e927
httpclient@4.5.6
4.5.13
2
library/elasticsearch:7.17.35e6ac15bf6a5
httpclient@4.5.10
4.5.13
2
mbentley/omada-controller:4.3f4e682274bed
httpclient@4.5.7
4.5.13
2
nacos/nacos-server:v2.1.0dcf04549c6d7
httpclient@4.5.12
4.5.13
2
opensearchproject/opensearch:2.1.04254021a8c71
httpclient@4.5.10
4.5.13
2
rodolpheche/wiremock:2.26.03be08a386092
httpclient@4.5.6
4.5.13
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
httpclient@4.5.10
4.5.13
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
httpclient@4.5.10
4.5.13
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
httpclient@4.5.2
4.5.13
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
httpclient@4.5.8
4.5.13
1
andrianrf/bpjstk-service:latest46abe878d9d8
httpclient@4.5.12
4.5.13
1
apache/druid:29.0.10cef139b6bf1
httpclient@4.5.2
4.5.13
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
httpclient@4.5.6
4.5.13
1
apacheignite/ignite:2.7.0d7deab68b8fa
httpclient@4.5.1
4.5.13
1
apache/nifi-registry:1.14.0090b7f87ec7f
httpclient@4.5.6
4.5.13
1
apache/nifi-registry:0.8.0974efa2f21da
httpclient@4.5.6
4.5.13
1
apachepulsar/pulsar:2.6.14db6ff0b4045
httpclient@4.5.5
4.5.13
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
httpclient@4.5.7
4.5.13
1
apache/skywalking-ui:8.1.067d50e4deff4
httpclient@4.5.3
4.5.13
1
apache/skywalking-ui:8.9.180530f0308a5
httpclient@4.5.3
4.5.13
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
aopalliance@1.0-20.module+el8.3.0+6804+157bd82e
apache-commons-cli@1.4-7.module+el8.3.0+6804+157bd82e
apache-commons-codec@1.13-3.module+el8.3.0+6804+157bd82e
apache-commons-io@1:2.6-6.module+el8.3.0+6804+157bd82e
apache-commons-lang3@3.9-4.module+el8.3.0+6804+157bd82e
atinject@1-31.20100611svn86.module+el8.3.0+6804+157bd82e
cdi-api@2.0.1-3.module+el8.3.0+6804+157bd82e
geronimo-annotation@1.0-26.module+el8.3.0+6804+157bd82e
google-guice@4.2.2-4.module+el8.3.0+6804+157bd82e
guava@28.1-3.module+el8.3.0+6804+157bd82e
httpclient@4.5.10
httpcomponents-client@4.5.10-3.module+el8.3.0+6804+157bd82e
httpcomponents-core@4.4.12-3.module+el8.3.0+6804+157bd82e
jansi@1.18-4.module+el8.3.0+6804+157bd82e
jsoup@1.12.1-3.module+el8.3.0+6804+157bd82e
jsr-305@0-0.25.20130910svn.module+el8.3.0+6804+157bd82e
maven@1:3.6.2-6.module+el8.4.0+9250+1786af37
maven-resolver@1.4.1-3.module+el8.3.0+6804+157bd82e
maven-shared-utils@3.2.1-0.4.module+el8.3.0+6804+157bd82e
maven-wagon@3.3.4-2.module+el8.3.0+6804+157bd82e
plexus-cipher@1.7-17.module+el8.3.0+6804+157bd82e
plexus-classworlds@2.6.0-4.module+el8.3.0+6804+157bd82e
plexus-containers@2.1.0-2.module+el8.3.0+6804+157bd82e
plexus-interpolation@1.26-3.module+el8.3.0+6804+157bd82e
plexus-sec-dispatcher@1.4-29.module+el8.3.0+6804+157bd82e
plexus-utils@3.3.0-3.module+el8.3.0+6804+157bd82e
sisu@0.3.4-2.module+el8.3.0+6804+157bd82e
slf4j@1.7.28-3.module+el8.3.0+6804+157bd82e
0:1.0-20.module+el8.6.0+13337+afcb49ec
0:1.4-7.module+el8.6.0+13337+afcb49ec
0:1.13-3.module+el8.6.0+13337+afcb49ec
1:2.6-6.module+el8.6.0+13337+afcb49ec
0:3.9-4.module+el8.6.0+13337+afcb49ec
0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec
0:2.0.1-3.module+el8.6.0+13337+afcb49ec
0:1.0-26.module+el8.6.0+13337+afcb49ec
0:4.2.2-4.module+el8.6.0+13337+afcb49ec
0:28.1-3.module+el8.6.0+13337+afcb49ec
4.5.13
0:4.5.10-4.module+el8.6.0+13337+afcb49ec
0:4.4.12-3.module+el8.6.0+13337+afcb49ec
0:1.18-4.module+el8.6.0+13337+afcb49ec
0:1.12.1-3.module+el8.6.0+13337+afcb49ec
0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec
1:3.6.2-7.module+el8.6.0+13337+afcb49ec
0:1.4.1-3.module+el8.6.0+13337+afcb49ec
0:3.2.1-0.4.module+el8.6.0+13337+afcb49ec
0:3.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7-17.module+el8.6.0+13337+afcb49ec
0:2.6.0-4.module+el8.6.0+13337+afcb49ec
0:2.1.0-2.module+el8.6.0+13337+afcb49ec
0:1.26-3.module+el8.6.0+13337+afcb49ec
0:1.4-29.module+el8.6.0+13337+afcb49ec
0:3.3.0-3.module+el8.6.0+13337+afcb49ec
0:0.3.4-2.module+el8.6.0+13337+afcb49ec
0:1.7.28-3.module+el8.6.0+13337+afcb49ec
1
assistiot/authorization_svr:latestdb9361dad79b
httpclient@4.5.9
4.5.13
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
httpclient@4.5.3
4.5.13
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
httpclient@4.5.10
4.5.13
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
httpclient@4.5.10
4.5.13
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
httpclient@4.5.6
4.5.13
1
atlassian/confluence-server:7.10.03b9222ab32ef
httpclient@4.5.10
4.5.13
1
atlassian/jira-software:8.14.037bc46cbec1a
httpclient@4.5.10
4.5.13
1
atomix/atomix:3.1.127738ff4f5c63
httpclient@4.5.2
4.5.13
1
bivas/presto:0.19605545994f806
httpclient@4.5.2
4.5.13
1
choerodon/event-store-service:0.8.03c94c97f6f69
httpclient@4.5.3
4.5.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.