StackRadar

CVE-2020-24553

Unscored

Advisory

Published 13 Jan 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.036
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
306
of 17,781 indexed, latest versions
Container images
288
deployed by those charts
Fix available
1 of 1
affected package

Cross-site scripting in net/http/cgi and net/http/fcgi

Carried by container images the latest versions of 306 of 17,781 indexed charts deploy, on 288 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+19 more1.14.8288
OSV records
GO-2021-0226
Also known as
BIT-golang-2020-24553

Charts affected

306 by stars
ChartLatestAffected imagesRadar Score
dnation-pingdnationcloud0.1.91 of 5See more

dnation-ping dnationcloud 0.1.9

1 of the 5 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.14.8

Open the chart page →

10,454
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.14.8

Open the chart page →

3,617
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
stdlib@go1.13.15
1.14.8

Open the chart page →

3,586
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.14.8

Open the chart page →

10,231
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.14.8

Open the chart page →

15,856
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.14.8

Open the chart page →

7,660
mesherykubesphere-stable0.5.01 of 13See more

meshery kubesphere-stable 0.5.0

1 of the 13 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
stdlib@go1.13.1
1.14.8

Open the chart page →

24,690
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.14.8

Open the chart page →

2,603
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
stdlib@go1.13.10
1.14.8

Open the chart page →

7,510
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.14.8

Open the chart page →

4,418
voice-biometricslumenvox2.0.11 of 26See more

voice-biometrics lumenvox 2.0.1

1 of the 26 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.14.8

Open the chart page →

70,741
mattermost-enterprise-editionmattermostVerified publisher2.6.1031 of 3See more

mattermost-enterprise-edition mattermost 2.6.103

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-04-25T00-43-23Z1806872732e1
stdlib@go1.13.10
1.14.8

Open the chart page →

3,600
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
stdlib@go1.14.6
1.14.8

Open the chart page →

3,254
hlf-ordowkin3.1.01 of 1See more

hlf-ord owkin 3.1.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.2.137294e05209b
stdlib@go1.14.4
1.14.8

Open the chart page →

3,350
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
stdlib@go1.14.4
1.14.8

Open the chart page →

3,688
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.14.8

Open the chart page →

31,844
prometheusprometheus-worawutchan13.0.03 of 6See more

prometheus prometheus-worawutchan 13.0.0

3 of the 6 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.14.8
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.14.8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.14.8

Open the chart page →

9,939
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.14.8

Open the chart page →

23,964
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.14.8

Open the chart page →

1,852
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
stdlib@go1.13.15
1.14.8

Open the chart page →

2,301
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
stdlib@go1.13.12
1.14.8

Open the chart page →

2,637
go-ratelimitsoftonic1.0.72 of 3See more

go-ratelimit softonic 1.0.7

2 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
stdlib@go1.14
1.14.8
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.14.8

Open the chart page →

5,098
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
stdlib@go1.14.6
1.14.8

Open the chart page →

2,591
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.14.8

Open the chart page →

2,307
gitwebhookproxystakaterVerified publisher0.2.791 of 1See more

gitwebhookproxy stakater 0.2.79

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.14.8

Open the chart page →

1,503
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
stdlib@go1.14.3
1.14.8

Open the chart page →

2,597
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
stdlib@go1.13.15
1.14.8

Open the chart page →

2,245
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
stdlib@go1.14.7
1.14.8

Open the chart page →

5,280
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
stdlib@go1.13.10
1.14.8

Open the chart page →

7,303
vearchvearch3.3.41 of 4See more

vearch vearch 3.3.4

1 of the 4 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.14.8

Open the chart page →

5,008
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
stdlib@go1.13.10
1.14.8

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
stdlib@go1.13.10
1.14.8

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
stdlib@go1.13.10
1.14.8

Open the chart page →

7,429
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
stdlib@go1.14.7
1.14.8

Open the chart page →

3,030
pi-hole-exporterwyrihaximusnetVerified publisher0.1.31 of 1See more

pi-hole-exporter wyrihaximusnet 0.1.3

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ekofr/pihole-exporter:0.0.109fdad6f352e0
stdlib@go1.14.7
1.14.8

Open the chart page →

1,809
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
stdlib@go1.13.10
1.14.8

Open the chart page →

7,447
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.14.8

Open the chart page →

7,209
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.14.8

Open the chart page →

2,239
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
stdlib@go1.13.15
1.14.8

Open the chart page →

2,488
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
stdlib@go1.15
1.14.8

Open the chart page →

2,730
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.14.8

Open the chart page →

45,363
hcloud-csi-driveratem181.5.11 of 6See more

hcloud-csi-driver atem18 1.5.1

1 of the 6 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.14.8

Open the chart page →

6,491
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
stdlib@go1.13.10
1.14.8

Open the chart page →

7,561
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.14.8

Open the chart page →

2,939
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
stdlib@go1.15
1.14.8

Open the chart page →

5,521
keptn-addonsazureorkestra0.1.01 of 4See more

keptn-addons azureorkestra 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
keptncontrib/prometheus-service:0.6.029969dd547de
stdlib@go1.13.7
1.14.8

Open the chart page →

10,621
prometheusazureorkestra14.8.01 of 6See more

prometheus azureorkestra 14.8.0

1 of the 6 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.14.8

Open the chart page →

9,661
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.14.8

Open the chart page →

3,037
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.14.8

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24553.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
stdlib@go1.13.10
1.14.8

Open the chart page →

7,342

Container images carrying it

288 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
stdlib@go1.13.10
1.14.8
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
stdlib@go1.13.10
1.14.8
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.14.8
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.14.8
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.14.8
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.14.8
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.14.8
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.14.8
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.14.8
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.14.8
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
stdlib@go1.13.4
1.14.8
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
stdlib@go1.14.6
1.14.8
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
stdlib@go1.14
1.14.8
1
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
stdlib@go1.15
1.14.8
1
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.14.8
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
stdlib@go1.14.1
1.14.8
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
stdlib@go1.13.8
1.14.8
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
stdlib@go1.13.8
1.14.8
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
stdlib@go1.13.8
1.14.8
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.14.8
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
stdlib@go1.14.4
1.14.8
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
stdlib@go1.13.1
1.14.8
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.14.8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.13.15
1.14.8
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
stdlib@go1.15
1.14.8
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.14.8
1
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.14.8
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.14.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.14.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.14.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.