StackRadar

CVE-2020-13959

Medium

Advisory

Published 12 Mar 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.057
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
None
affected package

Cross-site scripting (XSS) in Apache Velocity Tools

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
velocity-toolsmaven1.3, 1.4, 1.4-atlassian-2, 2.0no fix listed8
OSV records
GHSA-fh63-4r66-jc7v

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
velocity-tools@1.4-atlassian-2
no fix listed

Open the chart page →

1,490
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
velocity-tools@1.4
no fix listed

Open the chart page →

1,415
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
velocity-tools@1.3
no fix listed

Open the chart page →

8,636
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
velocity-tools@2.0
no fix listed
ibmcom/microclimate-theia:lateste17bdccc5030
velocity-tools@2.0
no fix listed

Open the chart page →

57,669
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
velocity-tools@1.3
no fix listed

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
velocity-tools@1.4
no fix listed

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2020-13959.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
velocity-tools@1.3
no fix listed

Open the chart page →

13,079

Container images carrying it

8 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
atlassian/confluence-server:7.10.03b9222ab32ef
velocity-tools@1.4
no fix listed
1
atlassian/crowd:7.2.3c81cc7d6bc9e
velocity-tools@1.4
no fix listed
1
atlassian/jira-software:8.14.037bc46cbec1a
velocity-tools@1.3
no fix listed
1
atlassian/jira-software:9.7.264a75aa4ec4e
velocity-tools@1.3
no fix listed
1
atlassian/jira-software:11.3.11e5548cd4eea8
velocity-tools@1.4-atlassian-2
no fix listed
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
velocity-tools@2.0
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
velocity-tools@2.0
no fix listed
1
xetusoss/archiva:v2.2.588f25242b9ee
velocity-tools@1.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.