StackRadar

CVE-2020-1957

Critical

Advisory

Published 7 May 2021In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.233
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Improper Authentication in Apache Shiro

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
shiro-coremaven1.2.3, 1.2.6, 1.4.01.5.26
OSV records
GHSA-26gr-cvq3-qxgf

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
1.5.2

Open the chart page →

11,553
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
shiro-core@1.4.0
1.5.2

Open the chart page →

8,063
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
1.5.2

Open the chart page →

11,553
cassandra-reapercloudnativeapp0.2.01 of 1See more

cassandra-reaper cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
thelastpickle/cassandra-reaper:1.3.09c53996c457d
shiro-core@1.2.3
1.5.2

Open the chart page →

5,078
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
shiro-core@1.4.0
1.5.2

Open the chart page →

2,837
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
shiro-core@1.4.0
1.5.2

Open the chart page →

26,356
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2020-1957.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
shiro-core@1.2.6
1.5.2

Open the chart page →

43,341

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mbentley/omada-controller:4.3f4e682274bed
shiro-core@1.4.0
1.5.2
2
graylog2/server:2.4.3-38ff28c66e6c1
shiro-core@1.4.0
1.5.2
1
ladeit/ladeit:latest962b665ffe82
shiro-core@1.4.0
1.5.2
1
library/neo4j:3.4.5-enterprisea1ba477fa412
shiro-core@1.4.0
1.5.2
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
shiro-core@1.2.6
1.5.2
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
shiro-core@1.2.3
1.5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.