StackRadar

CVE-2020-17521

Medium

Advisory

Published 9 Dec 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
28
of 17,781 indexed, latest versions
Container images
26
deployed by those charts
Fix available
2 of 2
affected packages

Information Disclosure in Apache Groovy

Carried by container images the latest versions of 28 of 17,781 indexed charts deploy, on 26 images.

Affected packageAffected versionsFixed inImages
groovy-allmaven2.2.2, 2.4.4, 2.4.8, 2.4.11+3 more2.4.2120
groovymaven2.4.6-indy, 2.4.7, 2.4.15, 2.5.5+3 more2.4.21, 2.5.14, 3.0.78
OSV records
GHSA-rcjj-h6gh-jf3r

Charts affected

28 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
groovy-all@2.4.15
2.4.21

Open the chart page →

10,732
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
groovy-all@2.4.11
2.4.21

Open the chart page →

7,166
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.21
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
groovy-all@2.4.4
2.4.21

Open the chart page →

20,837
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
groovy-all@2.4.11
2.4.21

Open the chart page →

7,335
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
groovy@3.0.3
3.0.7

Open the chart page →

18,042
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
groovy-all@2.4.4
2.4.21

Open the chart page →

8,198
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
groovy@2.5.7-indy
2.5.14

Open the chart page →

17,896
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
groovy-all@2.4.12
2.4.21

Open the chart page →

4,532
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.21

Open the chart page →

6,882
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
groovy@2.5.9
2.5.14

Open the chart page →

8,752
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
groovy-all@2.4.4
2.4.21

Open the chart page →

6,165
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
groovy@2.4.15
groovy-all@2.4.15
2.4.21
2.4.21

Open the chart page →

23,665
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
groovy@2.4.15
groovy-all@2.4.15
2.4.21
2.4.21

Open the chart page →

19,802
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
groovy@2.5.5
2.5.14

Open the chart page →

34,754
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.21
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
groovy-all@2.4.4
2.4.21

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.21

Open the chart page →

6,882
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
groovy-all@2.4.12
2.4.21

Open the chart page →

57,669
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
groovy-all@2.4.11
2.4.21

Open the chart page →

10,682
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
groovy-all@2.4.17
2.4.21

Open the chart page →

12,856
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
groovy@2.4.6-indy
2.4.21

Open the chart page →

4,911
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
groovy-all@2.2.2
2.4.21

Open the chart page →

13,607
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
groovy-all@2.2.2
2.4.21

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
groovy-all@2.2.2
2.4.21

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
groovy-all@2.2.2
2.4.21

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
groovy-all@2.2.2
2.4.21

Open the chart page →

13,100
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
groovy-all@2.4.17
2.4.21

Open the chart page →

4,946
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
groovy@2.4.7
2.4.21

Open the chart page →

8,554
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2020-17521.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
groovy-all@2.4.8
2.4.21

Open the chart page →

6,213

Container images carrying it

26 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.21
4
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
groovy-all@2.4.4
2.4.21
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
groovy-all@2.4.11
2.4.21
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
groovy@3.0.3
3.0.7
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
groovy@2.5.7-indy
2.5.14
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
groovy-all@2.2.2
2.4.21
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
groovy-all@2.2.2
2.4.21
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
groovy-all@2.2.2
2.4.21
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
groovy-all@2.2.2
2.4.21
1
gurolakman/ussigw-core:1.0.48739565c3ea2
groovy-all@2.2.2
2.4.21
1
ibmcom/microclimate-portal:latested5505e5c7ec
groovy-all@2.4.12
2.4.21
1
jenkinsci/jenkins:2.67a1f33f004659
groovy-all@2.4.11
2.4.21
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
groovy@2.5.5
2.5.14
1
just1not2/streama:1.10.48a2305192dec
groovy@2.4.7
2.4.21
1
library/elasticsearch:2.4.641ed3a1a16b6
groovy@2.4.6-indy
2.4.21
1
library/storm:2.4.0bd5d420506d6
groovy-all@2.4.4
2.4.21
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
groovy-all@2.4.8
2.4.21
1
microcks/microcks:0.8.0e3a3e0c67b09
groovy-all@2.4.15
2.4.21
1
pedrocesarti/jmeter-docker:3.314851f144f57
groovy-all@2.4.12
2.4.21
1
rundeck/rundeck:3.2.74d64fe56f767
groovy@2.4.15
groovy-all@2.4.15
2.4.21
2.4.21
1
rundeck/rundeck:3.0.16b13e8059ad72
groovy@2.4.15
groovy-all@2.4.15
2.4.21
2.4.21
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
groovy-all@2.4.4
2.4.21
1
sonatype/nexus3:3.58.1586060431b64
groovy-all@2.4.17
2.4.21
1
sslhep/hive-metastore:3.1.39e80af083079
groovy-all@2.4.11
2.4.21
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
groovy@2.5.9
2.5.14
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
groovy-all@2.4.17
2.4.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.