CVE-2020-15256
HighAdvisory
Published 19 Oct 2020In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.7
- base score, highest
- EPSS
- 0.015
- 74th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 9
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Prototype pollution in object-path
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 9 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| object-pathnpm | 0.9.2, 0.11.4 | 0.11.5 | 9 |
- OSV records
- GHSA-cwx2-736x-mf6w
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| backstagedeliveryheroVerified publisher | 0.1.15 | 1 of 2See more | 8,213 |
| graphql-gatewaygraphql-gatewayVerified publisher | 0.1.5 | 1 of 1See more | 1,660 |
| developer-dashboardcloud-native-toolkit | 1.4.1 | 1 of 1See more | 25,456 |
| streamsheetshelm-chartsVerified publisher | 0.2.3 | 4 of 8See more | 89,959 |
| backstagehelm-charts-nr | 0.1.15 | 1 of 2See more | 8,213 |
| ibm-microclimateibm-charts | 0.1.0 | 1 of 8See more | 57,669 |
| parkingsikalabs | 0.1.0 | 1 of 1See more | 3,696 |
Container images carrying it
9 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| martinaif/ | 43bc40a3da0e | object-path | 0.11.5 | 2 |
| hansehe/ | 58e09540afbc | object-path | 0.11.5 | 1 |
| ibmcom/ | ed5505e5c7ec | object-path | 0.11.5 | 1 |
| ondrejsika/ | b1fd497416c8 | object-path | 0.11.5 | 1 |
| ghcr.io/ | 0635f17c9d2c | object-path | 0.11.5 | 1 |
| ghcr.io/ | e34964e336c1 | object-path | 0.11.5 | 1 |
| ghcr.io/ | 0c5a3398d1e4 | object-path | 0.11.5 | 1 |
| ghcr.io/ | 8ba040e79ca0 | object-path | 0.11.5 | 1 |
| quay.io/ | 7a4b9fedc724 | object-path | 0.11.5 | 1 |