StackRadar

CVE-2020-15187

Low

Advisory

Published 24 May 2021In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.0
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
2 of 2
affected packages

plugin.yaml file allows for duplicate entries in helm

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
helm.sh/helm/v3golangv3.0.2, v3.0.3, v3.1.0, v3.2.0+2 more3.3.28
helmgolang2.7.2, 2.12.1, 2.14.32.16.113
OSV records
GHSA-c52f-pq47-2r9j
Also known as
BIT-helm-2020-15187

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
helm.sh/helm/v3@v3.0.2
3.3.2

Open the chart page →

4,154
mesherykubesphere-stable0.5.01 of 13See more

meshery kubesphere-stable 0.5.0

1 of the 13 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
layer5/meshery-nsm:stable-latestebd6a8faf21f
helm.sh/helm/v3@v3.3.1
3.3.2

Open the chart page →

24,690
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
helm.sh/helm/v3@v3.0.3
3.3.2

Open the chart page →

7,486
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
helm@2.7.2
2.16.11

Open the chart page →

57,669
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
helm.sh/helm/v3@v3.2.0
3.3.2

Open the chart page →

3,812
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
helm.sh/helm/v3@v3.2.0
3.3.2

Open the chart page →

26,356
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
helm.sh/helm/v3@v3.1.0
3.3.2

Open the chart page →

9,880
flaggermesosphere0.21.01 of 2See more

flagger mesosphere 0.21.0

1 of the 2 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
weaveworks/flagger-loadtester:0.9.03cdac6928a63
helm@2.14.3
2.16.11

Open the chart page →

6,048
argo-cdmesosphere-stable0.5.41 of 4See more

argo-cd mesosphere-stable 0.5.4

1 of the 4 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
argoproj/argocd:v1.2.1b0230853357d
helm@2.12.1
2.16.11

Open the chart page →

1,462
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
helm.sh/helm/v3@v3.0.2
3.3.2

Open the chart page →

11,151
quarksquarks7.0.1+0.g5396b111 of 5See more

quarks quarks 7.0.1+0.g5396b11

1 of the 5 container images this version deploys carry CVE-2020-15187.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
helm.sh/helm/v3@v3.3.0
3.3.2

Open the chart page →

18,197

Container images carrying it

11 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
argoproj/argocd:v1.2.1b0230853357d
helm@2.12.1
2.16.11
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
helm.sh/helm/v3@v3.0.3
3.3.2
1
devspacecloud/manager:0.3.349c397413f7b
helm.sh/helm/v3@v3.1.0
3.3.2
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
helm@2.7.2
2.16.11
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
helm.sh/helm/v3@v3.2.0
3.3.2
1
layer5/meshery-nsm:stable-latestebd6a8faf21f
helm.sh/helm/v3@v3.3.1
3.3.2
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
helm.sh/helm/v3@v3.0.2
3.3.2
1
sstarcher/helm-exporter:0.5.011769d01ba35
helm.sh/helm/v3@v3.0.2
3.3.2
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
helm@2.14.3
2.16.11
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
helm.sh/helm/v3@v3.3.0
3.3.2
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
helm.sh/helm/v3@v3.2.0
3.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.