StackRadar

CVE-2020-1971

Medium

Advisory

Published 8 Dec 2020In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.071
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
954
of 17,787 indexed, latest versions
Container images
780
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 954 of 17,787 indexed charts deploy, on 780 images.

Affected packageAffected versionsFixed inImages
opensslapk1.1.1a-r1, 1.1.1b-r1, 1.1.1c-r0, 1.1.1d-r0+5 more1.1.1i-r0379
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+27 more1.0.1f-1ubuntu2.27+esm2, 1.0.2g-1ubuntu4.18, 1.1.0l-1~deb9u2, 1.1.1-1ubuntu2.1~18.04.7+2 more361
openssl1.0deb1.0.2l-2, 1.0.2l-2+deb9u1, 1.0.2l-2+deb9u2, 1.0.2l-2+deb9u3+8 more1.0.2n-1ubuntu5.5, 1.0.2u-1~deb9u390
opensslrpm1:1.0.2k-16.el7_6.1, 1:1.0.2k-19.el7, 1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1+4 more1:1.0.2k-21.el7_9, 1:1.1.1c-16.el8_2, 1:1.1.1g-12.el8_330
openssl-1_1rpm1.1.0i-14.6.1, 1.1.0i-lp151.8.3.1, 1.1.1d-11.6.11.1.0i-14.12.1, 1.1.0i-lp151.8.12.2, 1.1.1d-11.12.110
OSV records
ALPINE-CVE-2020-1971RHSA-2020:5422RHSA-2020:5476RHSA-2020:5566UBUNTU-CVE-2020-1971DLA-2492-1DLA-2493-1DSA-4807-1openSUSE-SU-2020:2245-1SUSE-SU-2020:3720-1SUSE-SU-2020:3721-1
Also known as
RHSA-2020:5588, RHSA-2020:5623, RHSA-2020:5637, RHSA-2020:5642, USN-4662-1, USN-4745-1

Charts affected

954 by stars
ChartLatestAffected imagesRadar Score
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-1971.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
openssl@1.1.1g-r0
1.1.1i-r0

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-1971.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
openssl@1.1.1g-r0
1.1.1i-r0

Open the chart page →

3,023
helmexampleyunpeng-helmexample0.1.01 of 1See more

helmexample yunpeng-helmexample 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-1971.

Container imageDigestPackageFixed in
library/nginx:1.16.03e373fd5b8d4
openssl@1.1.0k-1~deb9u1
1.1.0l-1~deb9u2

Open the chart page →

702
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-1971.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
openssl@1.1.1d-0+deb10u3
1.1.1d-0+deb10u4

Open the chart page →

1,138

Container images carrying it

780 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
openssl@1.1.1d-0+deb10u2
1.1.1d-0+deb10u4
1
fluent/fluent-bit:1.3.73ae8c4ee81c5
openssl@1.1.0l-1~deb9u1
1.1.0l-1~deb9u2
1
fluent/fluent-bit:1.1.0b89ff3889a67
openssl@1.1.0j-1~deb9u1
1.1.0l-1~deb9u2
1
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
openssl@1.1.0j-1~deb9u1
openssl1.0@1.0.2q-1~deb9u1
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
openssl@1.1.1d-0+deb10u3
1.1.1d-0+deb10u4
1
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
openssl@1.1.0k-1~deb9u1
1.1.0l-1~deb9u2
1
folioci/mod-marccat:latest1b57d690d568
openssl@1.1.1d-r0
1.1.1i-r0
1
foomo/pagespeed_exporter:2.1.2b21330d692e3
openssl@1.1.1g-r0
1.1.1i-r0
1
forchaladtest/testwebapp:0.15909cf64ef53
openssl@1.1.1d-0+deb10u2
1.1.1d-0+deb10u4
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.7
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.7
1
free5gmano/nextepc-mongodb:latest36f806935519
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.18
1
gabekangas/owncast:0.0.797461aedb580
openssl@1.1.1g-r0
1.1.1i-r0
1
galaxy/galaxy-init:v18.010267bad550e6
openssl@1.0.1f-1ubuntu2.25
1.0.1f-1ubuntu2.27+esm2
1
galaxy/galaxy-stable:v18.018e577a626dfd
openssl@1.0.1f-1ubuntu2.25
1.0.1f-1ubuntu2.27+esm2
1
garugaru/presto-loadbalancer:v0.1.589d66d117029
openssl@1.1.1g-r0
1.1.1i-r0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.7
1.0.2n-1ubuntu5.5
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
openssl@1.1.0j-1~deb9u1
1.1.0l-1~deb9u2
1
gitea/gitea:1.12.485416d6f65fe
openssl@1.1.1g-r0
1.1.1i-r0
1
gitea/gitea:1.13.0d5ab14cd29af
openssl@1.1.1g-r0
1.1.1i-r0
1
gitlab/gitlab-runner:alpine-v12.3.0a83c15bda342
openssl@1.1.1b-r1
1.1.1i-r0
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
openssl@1.1.1g-r0
1.1.1i-r0
1
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
openssl@1.1.1b-r1
1.1.1i-r0
1
gocd/gocd-server:v19.3.02da45cb09d57
openssl@1.1.1b-r1
1.1.1i-r0
1
gogs/gogs:0.12.30195b095d0b2
openssl@1.1.1g-r0
1.1.1i-r0
1
gogs/gogs:0.12.1420d53bb7277
openssl@1.1.1g-r0
1.1.1i-r0
1
golenski/fibonacci-front:2.0.048cfd60b8413
openssl@1.1.1g-r0
1.1.1i-r0
1
gomods/athens:v0.8.1d714c7ff0231
openssl@1.1.1d-r3
1.1.1i-r0
1
gomods/athens:v0.11.0efb811df7844
openssl@1.1.1d-r3
1.1.1i-r0
1
gotson/komga:0.99.49b15ea6bfc30
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.7
1
grafana/grafana:6.6.0052147d7e0ec
openssl@1.1.1d-r4
1.1.1i-r0
1
grafana/grafana:5.2.1104f434d47c8
openssl@1.1.0f-3+deb9u2
openssl1.0@1.0.2l-2+deb9u3
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
grafana/grafana:7.3.315b977f5207d
openssl@1.1.1g-r0
1.1.1i-r0
1
grafana/grafana:7.3.46d42886b3ebe
openssl@1.1.1g-r0
1.1.1i-r0
1
grafana/grafana:7.2.1733842cca5bd
openssl@1.1.1g-r0
1.1.1i-r0
1
grafana/grafana:6.4.28c2238eea9d3
openssl@1.1.1d-r2
1.1.1i-r0
1
grafana/grafana:6.2.09e7fe9c7903a
openssl@1.1.0j-1~deb9u1
openssl1.0@1.0.2r-1~deb9u1
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
grafana/grafana:5.1.0a6b37f9afdd9
openssl@1.1.0f-3+deb9u2
openssl1.0@1.0.2l-2+deb9u3
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
grafana/grafana:5.2.2b5591419cfa3
openssl@1.1.0f-3+deb9u2
openssl1.0@1.0.2l-2+deb9u3
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
grafana/grafana:6.4.3bd55ea2bad17
openssl@1.1.1d-r2
1.1.1i-r0
1
grafana/grafana:6.5.1befcd84da2c1
openssl@1.1.1d-r2
1.1.1i-r0
1
grafana/loki:2.0.077e138f81a8e
openssl@1.1.1g-r0
1.1.1i-r0
1
grafana/promtail:2.0.05fd12edcc694
openssl@1.1.0l-1~deb9u1
1.1.0l-1~deb9u2
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
openssl@1.1.1g-r0
1.1.1i-r0
1
guacamole/guacamole:1.1.0333a7f40c145
openssl@1.1.0j-1~deb9u1
openssl1.0@1.0.2r-1~deb9u1
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
guacamole/guacd:1.1.02288530a4d1c
openssl@1.1.1d-0+deb10u2
1.1.1d-0+deb10u4
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
openssl@1.1.0l-1~deb9u1
openssl1.0@1.0.2u-1~deb9u1
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1
halkeye/hubot:latest9764d2202130
openssl@1.1.1g-r0
1.1.1i-r0
1
halkeye/matrix-ircd:latest1ddae9d0f1c7
openssl@1.1.1d-0+deb10u2
1.1.1d-0+deb10u4
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
openssl@1.1.0j-1~deb9u1
openssl1.0@1.0.2r-1~deb9u1
1.1.0l-1~deb9u2
1.0.2u-1~deb9u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.