StackRadar

CVE-2020-22083

Critical

Advisory

Published 17 Dec 2020In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.064
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
1 of 1
affected package

jsonpickle unsafe deserialization

Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
jsonpicklepypi1.2, 1.3, 1.4.1, 1.4.21.4.25
OSV records
GHSA-j66q-qmrc-89rx
Also known as
PYSEC-2020-49

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-22083.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
jsonpickle@1.4.2
no fix listed

Open the chart page →

11,205
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-22083.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
jsonpickle@1.3
1.4.2

Open the chart page →

3,891
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2020-22083.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
jsonpickle@1.2
1.4.2

Open the chart page →

27,728
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-22083.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
jsonpickle@1.2
1.4.2

Open the chart page →

24,335
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2020-22083.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
jsonpickle@1.4.1
1.4.2

Open the chart page →

4,422
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2020-22083.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
jsonpickle@1.4.1
1.4.2

Open the chart page →

4,422

Container images carrying it

5 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
larribas/mlflow:1.9.105ccb0b46bfb
jsonpickle@1.4.1
1.4.2
2
camptocamp/ekorre:0.1.035c91d5fda04
jsonpickle@1.3
1.4.2
1
opendatacube/restcube:latest91870111837c
jsonpickle@1.2
1.4.2
1
opendatacube/wms:latest1b90cdf68831
jsonpickle@1.2
1.4.2
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
jsonpickle@1.4.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.