StackRadar

CVE-2020-15366

Medium

Advisory

Published 15 Jul 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
125
of 17,781 indexed, latest versions
Container images
123
deployed by those charts
Fix available
1 of 2
affected packages

Prototype Pollution in Ajv

Carried by container images the latest versions of 125 of 17,781 indexed charts deploy, on 123 images.

Affected packageAffected versionsFixed inImages
ajvnpm4.11.8, 5.2.3, 5.5.2, 6.4.0+9 more6.12.3123
node-ajvdeb6.10.2-1no fix listed2
OSV records
GHSA-v88g-cgmw-v5xwUBUNTU-CVE-2020-15366

Charts affected

125 by stars
ChartLatestAffected imagesRadar Score
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
ajv@5.2.3
6.12.3

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
ajv@5.2.3
6.12.3

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
ajv@5.5.2
6.12.3

Open the chart page →

36,215
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
ajv@5.5.2
6.12.3

Open the chart page →

1,986
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
ajv@5.5.2
6.12.3
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ajv@5.5.2
6.12.3

Open the chart page →

19,720
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
ajv@5.5.2
6.12.3

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
ajv@5.5.2
6.12.3

Open the chart page →

20,462
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ajv@6.12.2
6.12.3

Open the chart page →

5,215
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ajv@5.5.2
6.12.3

Open the chart page →

5,582
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
ajv@5.5.2
6.12.3

Open the chart page →

3,638
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
ajv@6.10.2
6.12.3

Open the chart page →

3,696
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ajv@5.5.2
6.12.3

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ajv@5.5.2
6.12.3

Open the chart page →

29,220
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ajv@5.5.2
6.12.3

Open the chart page →

4,967
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
ajv@4.11.8
6.12.3

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
ajv@4.11.8
6.12.3

Open the chart page →

12,460
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
ajv@6.10.2
node-ajv@6.10.2-1
6.12.3
no fix listed

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
ajv@5.5.2
6.12.3

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
ajv@6.7.0
6.12.3

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
ajv@6.10.0
6.12.3

Open the chart page →

3,576
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
ajv@5.5.2
6.12.3

Open the chart page →

2,838
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
ajv@6.10.2
6.12.3

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
ajv@5.5.2
6.12.3

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
ajv@5.5.2
6.12.3

Open the chart page →

22,665
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ajv@5.5.2
6.12.3

Open the chart page →

1,309

Container images carrying it

123 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gristlabs/grist:0.7.96e71b1914a7e
ajv@6.12.2
6.12.3
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ajv@5.5.2
6.12.3
1
halkeye/hubot:latest9764d2202130
ajv@5.5.2
6.12.3
1
halkeye/irslackd:latest7638bfba70b0
ajv@6.10.0
6.12.3
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
ajv@5.5.2
6.12.3
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
ajv@5.2.3
6.12.3
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
ajv@6.5.3
6.12.3
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
ajv@5.5.2
6.12.3
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
ajv@5.2.3
6.12.3
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ajv@5.2.3
6.12.3
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
ajv@5.5.2
6.12.3
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
ajv@5.5.2
6.12.3
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
ajv@5.5.2
6.12.3
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ajv@5.2.3
6.12.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
ajv@4.11.8
6.12.3
1
ibmcom/microclimate-theia:lateste17bdccc5030
ajv@5.2.3
6.12.3
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ajv@5.5.2
6.12.3
1
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
ajv@5.5.2
6.12.3
1
jayfong/yapi:1.10.2163e5d621910
ajv@4.11.8
6.12.3
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
ajv@5.5.2
6.12.3
1
konradkleine/docker-registry-frontend:v2181aad54ee64
ajv@4.11.8
6.12.3
1
koumoul/capture:17108d47be3b2
ajv@5.5.2
6.12.3
1
koumoul/openapi-viewer:18eeca2e8285b
ajv@5.2.3
6.12.3
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
ajv@6.9.2
6.12.3
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ajv@6.9.2
6.12.3
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
ajv@5.5.2
6.12.3
1
lavandadelpatio/frontend:latest501c3f31e0bc
ajv@6.12.2
6.12.3
1
linuxserver/cloud9:latest45c5fe102ff3
ajv@4.11.8
6.12.3
1
linuxserver/codimd:latestb801bbcf6386
ajv@5.5.2
6.12.3
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
ajv@6.10.2
node-ajv@6.10.2-1
6.12.3
no fix listed
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ajv@5.5.2
6.12.3
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
ajv@5.5.2
6.12.3
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
ajv@5.5.2
6.12.3
1
minddocdev/hubot:0.1.96c60b11a4fa7
ajv@5.5.2
6.12.3
1
mozilla/sentencecollector:2.0.91da6ff5c4895
ajv@6.10.2
6.12.3
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ajv@5.2.3
6.12.3
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ajv@6.10.0
6.12.3
1
nocodb/nocodb:0.301.5d9516f0bf546
ajv@6.10.2
6.12.3
1
nodered/node-red-docker:0.19.6-v8070643219ea2
ajv@6.9.2
6.12.3
1
omecproject/onos-progran:1.0.05715e5648aa0
ajv@5.2.3
6.12.3
1
ondrejsika/parking:latestb1fd497416c8
ajv@6.10.2
6.12.3
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
ajv@5.5.2
6.12.3
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
ajv@5.5.2
6.12.3
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ajv@5.5.2
6.12.3
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
ajv@6.8.1
6.12.3
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
ajv@5.5.2
6.12.3
1
polonel/trudesk:1.2.60cf6513f6fe3
ajv@6.7.0
6.12.3
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
ajv@4.11.8
6.12.3
1
socialmediamacroscope/smile_server:0.3.31a528c794270
ajv@6.7.0
6.12.3
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
ajv@6.10.2
node-ajv@6.10.2-1
6.12.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.