StackRadar

CVE-2020-22218

High

Advisory

Published 22 Aug 2023In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libssh2 security update

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
libssh2rpm1.4.3-12.el7_6.2, 1.4.3-12.el7_6.3, 1.8.0-3.el7, 1.8.0-4.el70:1.8.0-4.el7_9.128
libssh2deb1.5.0-2ubuntu0.1, 1.8.0-2.1build11.5.0-2ubuntu0.1+esm2, 1.8.0-2.1ubuntu0.13
OSV records
RHSA-2023:5615UBUNTU-CVE-2020-22218
Also known as
USN-6371-1

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
rke2-multusrke2-charts3.7.1-build20210416012 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

2 of the 2 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
rancher/hardened-cni-plugins:v0.9.1-build20210414be3c1d469bf7
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

4,519
rke2-canalrke2-charts3.13.32 of 2See more

rke2-canal rke2-charts 3.13.3

2 of the 2 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

6,996
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

20,900
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

4,624
datadog-operatordatadog-test0.1.21 of 1See more

datadog-operator datadog-test 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
datadog/operator:0.3.117f08a860090
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1

Open the chart page →

3,980
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libssh2@1.8.0-2.1build1
1.8.0-2.1ubuntu0.1

Open the chart page →

17,929
ibm-app-navigatoribm-charts1.0.15 of 5See more

ibm-app-navigator ibm-charts 1.0.1

5 of the 5 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
ibmcom/app-nav-controller:1.0.1ee4624ba513d
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
ibmcom/app-nav-init:1.0.1240ff499eb5b
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.06 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

6 of the 6 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1

Open the chart page →

39,349
ibm-open-libertyibm-charts1.10.01 of 1See more

ibm-open-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1

Open the chart page →

2,063
ibm-open-liberty-springibm-charts1.10.01 of 1See more

ibm-open-liberty-spring ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1

Open the chart page →

2,063
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1

Open the chart page →

4,505
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1

Open the chart page →

2,063
helm-controllerkubedex0.4.01 of 1See more

helm-controller kubedex 0.4.0

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
kubedex/helm-controller:v1.0.14f1008c51ef9
libssh2@1.4.3-12.el7_6.3
0:1.8.0-4.el7_9.1

Open the chart page →

2,422
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm2

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm2

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm2

Open the chart page →

29,124
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

5,942
rke2-kube-proxyrke2-charts1.20.21 of 1See more

rke2-kube-proxy rke2-charts 1.20.2

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
rancher/hardened-kube-proxy:v1.20.2d0600143c23c
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

1,552
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libssh2@1.8.0-2.1build1
1.8.0-2.1ubuntu0.1

Open the chart page →

30,687
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2020-22218.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
altinity/metrics-exporter:0.16.185b4fdbae053
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1

Open the chart page →

8,707

Container images carrying it

31 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm2
3
altinity/clickhouse-operator:0.16.1db7dde971407
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
altinity/metrics-exporter:0.16.185b4fdbae053
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
datadog/operator:0.3.117f08a860090
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
1
ibmcom/app-nav-controller:1.0.1ee4624ba513d
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
libssh2@1.4.3-12.el7_6.2
0:1.8.0-4.el7_9.1
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
kubedex/helm-controller:v1.0.14f1008c51ef9
libssh2@1.4.3-12.el7_6.3
0:1.8.0-4.el7_9.1
1
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-calico:v3.13.36d2cd61a338b
libssh2@1.8.0-3.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-cni-plugins:v0.9.1-build20210414be3c1d469bf7
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-kube-proxy:v1.20.2d0600143c23c
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libssh2@1.8.0-2.1build1
1.8.0-2.1ubuntu0.1
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
libssh2@1.8.0-4.el7
0:1.8.0-4.el7_9.1
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libssh2@1.8.0-2.1build1
1.8.0-2.1ubuntu0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.