StackRadar

CVE-2020-15366

Medium

Advisory

Published 15 Jul 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
125
of 17,781 indexed, latest versions
Container images
123
deployed by those charts
Fix available
1 of 2
affected packages

Prototype Pollution in Ajv

Carried by container images the latest versions of 125 of 17,781 indexed charts deploy, on 123 images.

Affected packageAffected versionsFixed inImages
ajvnpm4.11.8, 5.2.3, 5.5.2, 6.4.0+9 more6.12.3123
node-ajvdeb6.10.2-1no fix listed2
OSV records
GHSA-v88g-cgmw-v5xwUBUNTU-CVE-2020-15366

Charts affected

125 by stars
ChartLatestAffected imagesRadar Score
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ajv@5.5.2
6.12.3

Open the chart page →

11,174
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
ajv@6.8.1
6.12.3

Open the chart page →

3,005
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
ajv@5.5.2
6.12.3

Open the chart page →

3,337
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
ajv@5.5.2
6.12.3

Open the chart page →

5,941
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ajv@6.10.0
6.12.3

Open the chart page →

4,043
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
ajv@5.5.2
6.12.3

Open the chart page →

2,689
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
ajv@5.5.2
6.12.3
governify/director:v1.4.0608c6940bb98
ajv@5.5.2
6.12.3
governify/registry:v3.4.0d3f37f4f8168
ajv@5.5.2
6.12.3
governify/render:v2.2.0daeca1ce28e6
ajv@5.5.2
6.12.3
governify/reporter:v2.2.038595913458f
ajv@5.5.2
6.12.3

Open the chart page →

22,512
Governify-Falcongovernify0.1.05 of 10See more

Governify-Falcon governify 0.1.0

5 of the 10 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
ajv@5.5.2
6.12.3
governify/director:v1.4.0608c6940bb98
ajv@5.5.2
6.12.3
governify/registry:v3.4.0d3f37f4f8168
ajv@5.5.2
6.12.3
governify/render:v2.2.0daeca1ce28e6
ajv@5.5.2
6.12.3
governify/reporter:v2.2.038595913458f
ajv@5.5.2
6.12.3

Open the chart page →

24,319
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ajv@5.5.2
6.12.3

Open the chart page →

3,642
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
ajv@5.5.2
6.12.3

Open the chart page →

2,116
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
ajv@6.10.0
6.12.3

Open the chart page →

2,064
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
ajv@5.5.2
6.12.3

Open the chart page →

3,003
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
ajv@6.12.2
6.12.3
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
ajv@6.12.2
6.12.3
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
ajv@6.12.2
6.12.3
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
ajv@6.12.2
6.12.3

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
ajv@5.5.2
6.12.3

Open the chart page →

8,213
http-folderhttp-folder2.0.01 of 1See more

http-folder http-folder 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
aureliengasser/http-folder:1.1.111c4318c2571
ajv@5.5.2
6.12.3

Open the chart page →

1,847
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
ajv@5.5.2
6.12.3

Open the chart page →

2,656
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
ajv@5.2.3
6.12.3
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ajv@5.2.3
6.12.3

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
ajv@5.5.2
6.12.3
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
ajv@5.5.2
6.12.3

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
ajv@5.5.2
6.12.3

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ajv@5.2.3
6.12.3
ibmcom/microclimate-portal:latested5505e5c7ec
ajv@4.11.8
6.12.3
ibmcom/microclimate-theia:lateste17bdccc5030
ajv@5.2.3
6.12.3

Open the chart page →

57,669
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ajv@5.5.2
6.12.3

Open the chart page →

4,505
indexer-chartindexer-application0.1.01 of 1See more

indexer-chart indexer-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ibarreche/cloud-indexer-ci:latestb7a08274e69f
ajv@5.5.2
6.12.3

Open the chart page →

3,289
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
ajv@5.5.2
6.12.3

Open the chart page →

18,980
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
ajv@4.11.8
6.12.3

Open the chart page →

4,614
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
ajv@4.11.8
6.12.3

Open the chart page →

6,454
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
ajv@5.5.2
6.12.3

Open the chart page →

4,185
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
ajv@5.5.2
6.12.3

Open the chart page →

12,527
kubeflowkromanow94-kubeflow0.5.11 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

1 of the 30 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ajv@6.9.2
6.12.3

Open the chart page →

70,530
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
ajv@5.5.2
6.12.3

Open the chart page →

9,378
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
ajv@5.5.2
6.12.3

Open the chart page →

9,880
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
ajv@6.10.2
node-ajv@6.10.2-1
6.12.3
no fix listed

Open the chart page →

17,779
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
ajv@6.10.2
6.12.3

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
ajv@6.12.2
6.12.3

Open the chart page →

3,651
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
ajv@5.5.2
6.12.3

Open the chart page →

5,287
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ajv@6.12.0
6.12.3

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ajv@6.12.0
6.12.3

Open the chart page →

7,027
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
ajv@5.5.2
6.12.3

Open the chart page →

12,847
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ajv@5.5.2
6.12.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.12.3

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ajv@5.5.2
6.12.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.12.3

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ajv@5.5.2
6.12.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.12.3

Open the chart page →

12,108
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ajv@5.5.2
6.12.3
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ajv@5.5.2
6.12.3
mojaloop/role-assignment-service:v2.1.0def4bf273721
ajv@5.5.2
6.12.3

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.12.3
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ajv@5.5.2
6.12.3

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ajv@5.5.2
6.12.3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ajv@5.5.2
6.12.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ajv@5.5.2
6.12.3
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ajv@5.5.2
6.12.3

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ajv@5.5.2
6.12.3

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ajv@5.5.2
6.12.3

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
ajv@5.5.2
6.12.3

Open the chart page →

2,316
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
ajv@4.11.8
6.12.3
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
ajv@4.11.8
6.12.3

Open the chart page →

7,048
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
ajv@6.10.2
6.12.3

Open the chart page →

6,684
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
ajv@4.11.8
6.12.3
socialmediamacroscope/smile_server:0.3.31a528c794270
ajv@6.7.0
6.12.3

Open the chart page →

109,294
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2020-15366.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
ajv@4.11.8
6.12.3
linuxserver/codimd:latestb801bbcf6386
ajv@5.5.2
6.12.3

Open the chart page →

27,465

Container images carrying it

123 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/web:1.14.033cfa863d8ce
ajv@5.5.2
6.12.3
1
testhubio/testhub-frontend:on-preme86c2db53be8
ajv@6.12.0
6.12.3
1
thelounge/thelounge:4.2.0-alpine639978459c3a
ajv@5.5.2
6.12.3
1
tzahi12345/youtubedl-material:4.23720b856bd2f
ajv@6.12.0
6.12.3
1
ubercadence/web:v3.29.58564a5b44a6d
ajv@5.5.2
6.12.3
1
wekanteam/wekan:v4.2268a51f0327df
ajv@5.5.2
6.12.3
1
willwill/kube-slack:v4.1.1d443017aae98
ajv@5.5.2
6.12.3
1
wiremind/scrapoxy:lateste7048929a676
ajv@5.5.2
6.12.3
1
zooz/predator:1.6f491d1f7a865
ajv@5.5.2
6.12.3
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
ajv@6.12.2
6.12.3
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
ajv@6.12.2
6.12.3
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
ajv@6.12.2
6.12.3
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
ajv@6.12.2
6.12.3
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
ajv@5.5.2
6.12.3
1
ghcr.io/leoquote/mergeable:latest451706815103
ajv@5.5.2
6.12.3
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
ajv@5.5.2
6.12.3
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
ajv@6.10.2
6.12.3
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
ajv@4.11.8
6.12.3
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
ajv@6.5.5
6.12.3
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
ajv@5.5.2
6.12.3
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
ajv@5.5.2
6.12.3
1
quay.io/wekan/wekan:v5.65cb17600883a3
ajv@5.5.2
6.12.3
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
ajv@5.5.2
6.12.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.