StackRadar

CVE-2020-14352

High

Advisory

Published 16 Sept 2024In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.0
base score, highest
EPSS
0.025
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

Red Hat Security Advisory: librepo security update

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
libreporpm1.8.1-7.el7, 1.9.2-1.el8, 1.10.3-3.el8, 1.11.0-2.el80:1.8.1-8.el7_9, 0:1.11.0-3.el8_219
OSV records
RHSA-2020:3658RHSA-2020:5012
Also known as
RHSA-2020:3749, RHSA-2020:3756

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
rke2-canalrke2-charts3.13.32 of 2See more

rke2-canal rke2-charts 3.13.3

2 of the 2 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

6,996
datadog-operatordatadog-test0.1.21 of 1See more

datadog-operator datadog-test 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
datadog/operator:0.3.117f08a860090
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

3,980
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2

Open the chart page →

5,792
ibm-app-navigatoribm-charts1.0.13 of 5See more

ibm-app-navigator ibm-charts 1.0.1

3 of the 5 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
ibmcom/app-nav-controller:1.0.1ee4624ba513d
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
ibmcom/app-nav-was-controller:1.0.1a6748792da26
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

39,349
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2

Open the chart page →

12,461
ibm-open-libertyibm-charts1.10.01 of 1See more

ibm-open-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

2,063
ibm-open-liberty-springibm-charts1.10.01 of 1See more

ibm-open-liberty-spring ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

2,063
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

2,063
ibm-ucv-prodibm-helm5.2.61 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

1 of the 16 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
librepo@1.9.2-1.el8
0:1.11.0-3.el8_2

Open the chart page →

12,105
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
librepo@1.10.3-3.el8
0:1.11.0-3.el8_2

Open the chart page →

9,854
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2

Open the chart page →

12,856
helm-controllerkubedex0.4.01 of 1See more

helm-controller kubedex 0.4.0

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
kubedex/helm-controller:v1.0.14f1008c51ef9
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9

Open the chart page →

2,422
cloud-native-javamcouliba0.1.01 of 1See more

cloud-native-java mcouliba 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
librepo@1.10.3-3.el8
0:1.11.0-3.el8_2

Open the chart page →

4,979
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2020-14352.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
librepo@1.10.3-3.el8
0:1.11.0-3.el8_2

Open the chart page →

11,151

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
anchore/anchore-engine:v0.7.1ed9b3badd17c
librepo@1.10.3-3.el8
0:1.11.0-3.el8_2
1
ctron/hawkbit-operator:0.1.48fdea8f76499
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2
1
datadog/operator:0.3.117f08a860090
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
ibmcom/app-nav-controller:1.0.1ee4624ba513d
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2
1
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2
1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
librepo@1.9.2-1.el8
0:1.11.0-3.el8_2
1
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
kubedex/helm-controller:v1.0.14f1008c51ef9
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
librepo@1.10.3-3.el8
0:1.11.0-3.el8_2
1
rancher/hardened-calico:v3.13.36d2cd61a338b
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
librepo@1.8.1-7.el7
0:1.8.1-8.el7_9
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
librepo@1.11.0-2.el8
0:1.11.0-3.el8_2
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
librepo@1.10.3-3.el8
0:1.11.0-3.el8_2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.