StackRadar

CVE-2020-15778

High

Advisory

Published 24 Jul 2020In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.130
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
258
of 17,781 indexed, latest versions
Container images
255
deployed by those charts
Fix available
1 of 2
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 258 of 17,781 indexed charts deploy, on 255 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+29 moreno fix listed246
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+1 more0:8.0p1-24.el89
OSV records
DEBIAN-CVE-2020-15778UBUNTU-CVE-2020-15778RHSA-2024:3166

Charts affected

258 by stars
ChartLatestAffected imagesRadar Score
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

28,858
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssh@1:10.0p1-7+deb13u4
no fix listed

Open the chart page →

4,423
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
no fix listed

Open the chart page →

14,358
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssh@1:10.0p1-7+deb13u4
no fix listed

Open the chart page →

2,476
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2020-15778.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

5,542

Container images carrying it

255 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
openssh@1:10.0p1-7
no fix listed
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
openssh@1:10.0p1-7
no fix listed
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
no fix listed
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
openssh@1:9.2p1-2+deb12u5
no fix listed
1
ghcr.io/firecrawl/firecrawl:2.11.33092ee28c20a0d
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
openssh@1:9.2p1-2+deb12u3
no fix listed
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
openssh@1:10.0p1-7
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
openssh@1:9.2p1-2+deb12u5
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
openssh@1:10.0p1-7
no fix listed
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
openssh@1:8.2p1-4ubuntu0.4
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
openssh@1:9.2p1-2+deb12u3
no fix listed
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
openssh@1:10.0p1-7+deb13u1
no fix listed
1
ghcr.io/moghtech/komodo-core:2.3.3bca73d0eee14
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssh@1:9.2p1-2+deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
openssh@1:9.2p1-2+deb12u7
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
openssh@1:9.2p1-2+deb12u6
no fix listed
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-033e56bdd1b90d
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssh@1:9.2p1-2+deb12u4
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssh@1:9.2p1-2+deb12u4
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/stac-utils/stac-fastapi-pgstac:6.4.0fa35b9519abb
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
openssh@1:9.2p1-2+deb12u7
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssh@1:9.2p1-2+deb12u4
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssh@1:9.2p1-2+deb12u3
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssh@1:9.2p1-2+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssh@1:9.2p1-2+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssh@1:9.2p1-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssh@1:9.2p1-2+deb12u1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
no fix listed
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
openssh@1:10.0p1-7+deb13u4
no fix listed
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
openssh@8.0p1-6.el8_4.2
0:8.0p1-24.el8
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
openssh@8.0p1-19.el8_8
0:8.0p1-24.el8
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
openssh@8.0p1-6.el8_4.2
0:8.0p1-24.el8
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
openssh@8.0p1-4.el8_1
0:8.0p1-24.el8
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
openssh@8.0p1-15.el8_6.3
0:8.0p1-24.el8
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssh@1:7.2p2-4ubuntu2.10
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.