StackRadar

CVE-2020-15522

Medium

Advisory

Published 20 May 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
105
of 17,781 indexed, latest versions
Container images
105
deployed by those charts
Fix available
6 of 7
affected packages

Timing based private key exposure in Bouncy Castle

Carried by container images the latest versions of 105 of 17,781 indexed charts deploy, on 105 images.

Affected packageAffected versionsFixed inImages
bouncycastledeb1.61-1no fix listed1
bcprov-jdk15onmaven1.50, 1.51, 1.52, 1.53+11 more1.6695
bcprov-ext-jdk15onmaven1.50, 1.59, 1.60, 1.61+1 more1.6616
bc-fipsmaven1.0.1, 1.0.21.0.2.113
bcprov-jdk15to18maven1.63, 1.651.664
bcprov-jdk16maven1.461.662
BouncyCastlenuget1.8.51.8.71
OSV records
GHSA-6xx3-rg99-gc3pUBUNTU-CVE-2020-15522

Charts affected

105 by stars
ChartLatestAffected imagesRadar Score
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2020-15522.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
bcprov-jdk15on@1.57
1.66

Open the chart page →

9,397
webencryptorwebencryptor1.1.01 of 1See more

webencryptor webencryptor 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-15522.

Container imageDigestPackageFixed in
beubi/webencryptor:latesta02c2e200920
BouncyCastle@1.8.5
1.8.7

Open the chart page →

1,968
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-15522.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.1

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2020-15522.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
bcprov-jdk15on@1.60
1.66

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-15522.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
bcprov-jdk15on@1.58
1.66

Open the chart page →

3,480

Container images carrying it

105 by charts deploying them

A fixed version is listed for 6 of the 7 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
bcprov-jdk15to18@1.65
1.66
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
bcprov-jdk15on@1.60
1.66
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
bcprov-jdk16@1.46
1.66
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
bcprov-jdk16@1.46
1.66
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
bcprov-jdk15on@1.65
1.66
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.