StackRadar

CVE-2020-25613

High

Advisory

Published 1 Oct 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.038
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
42
deployed by those charts
Fix available
3 of 3
affected packages

WEBRick vulnerable to HTTP Request/Response Smuggling

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 42 images.

Affected packageAffected versionsFixed inImages
webrickgem1.4.2, 1.6.01.4.4, 1.6.139
ruby2.3deb2.3.1-2~16.04.5, 2.3.3-1+deb9u42.3.1-2~ubuntu16.04.15, 2.3.3-1+deb9u93
ruby2.5rpm2.5.8-4.11.12.5.8-4.14.17
OSV records
GHSA-gwfg-cqmg-cf8fUBUNTU-CVE-2020-25613DLA-2391-1SUSE-SU-2021:0933-1
Also known as
BIT-ruby-2020-25613, BIT-ruby-min-2020-25613, USN-4882-1

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
ceticasbl/pg-ldap-sync:latest6c0aa7567145
webrick@1.4.2
1.4.4

Open the chart page →

52,919
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
webrick@1.4.2
1.4.4

Open the chart page →

18,137
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-4.1.0-312808e2dfa810
webrick@1.4.2
1.4.4

Open the chart page →

6,110
gollumgeek-cookbookVerified publisher3.4.21 of 3See more

gollum geek-cookbook 3.4.2

1 of the 3 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
gollumorg/gollum:latest7cd5305a3cf7
webrick@1.6.0
1.6.1

Open the chart page →

4,629
docker-registry-browsergmelilloVerified publisher0.1.21 of 1See more

docker-registry-browser gmelillo 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
klausmeyer/docker-registry-browser:1.3.5430a440d95af
webrick@1.6.0
1.6.1

Open the chart page →

4,108
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
webrick@1.6.0
1.6.1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
webrick@1.6.0
1.6.1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
webrick@1.6.0
1.6.1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
webrick@1.6.0
1.6.1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
webrick@1.6.0
1.6.1

Open the chart page →

113,791
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.17.02b081e3c86dd
webrick@1.6.0
1.6.1

Open the chart page →

20,671
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
webrick@1.4.2
1.4.4

Open the chart page →

18,980
fluentdbryanalves0.1.01 of 1See more

fluentd bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
bryanalves/fluentd:0.5d3605be4b178
webrick@1.4.2
1.4.4

Open the chart page →

723
honeywell-exporterbryanalves0.1.11 of 1See more

honeywell-exporter bryanalves 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
webrick@1.4.2
1.4.4

Open the chart page →

5,437
smart-exporterbryanalves0.2.21 of 1See more

smart-exporter bryanalves 0.2.2

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
bryanalves/smart_exporter:0.2af47dfbb9413
webrick@1.4.2
1.4.4

Open the chart page →

4,131
fluentd-cloudwatchcloudnativeapp0.9.01 of 2See more

fluentd-cloudwatch cloudnativeapp 0.9.0

1 of the 2 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
ruby2.3@2.3.3-1+deb9u4
2.3.3-1+deb9u9

Open the chart page →

1,342
fluentd-kubernetes-awscloudposse0.2.11 of 2See more

fluentd-kubernetes-aws cloudposse 0.2.1

1 of the 2 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
webrick@1.4.2
1.4.4

Open the chart page →

1,305
coralogix-fluentddevtron1.0.31 of 1See more

coralogix-fluentd devtron 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.4.4

Open the chart page →

750
coralogix-fluentddevtron-labs1.0.31 of 1See more

coralogix-fluentd devtron-labs 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.4.4

Open the chart page →

750
gwangju_2-3gwangju2-30.1.01 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

1 of the 5 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
webrick@1.4.2
1.4.4

Open the chart page →

6,491
coralogix-fluentdhelmtest1.0.41 of 1See more

coralogix-fluentd helmtest 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.4.4

Open the chart page →

750
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
webrick@1.4.2
1.4.4

Open the chart page →

18,980
gitlabkubesphereVerified publisher4.2.36 of 17See more

gitlab kubesphere 4.2.3

6 of the 17 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
webrick@1.4.2
1.4.4
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
webrick@1.4.2
1.4.4
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
webrick@1.4.2
1.4.4
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
webrick@1.4.2
1.4.4
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
webrick@1.4.2
1.4.4
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
webrick@1.4.2
1.4.4

Open the chart page →

38,133
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-details-v1:1.13.0108d022f64f0
webrick@1.4.2
1.4.4

Open the chart page →

9,378
fluentd-papertrailmozilla0.2.21 of 1See more

fluentd-papertrail mozilla 0.2.2

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
webrick@1.4.2
1.4.4

Open the chart page →

1,001
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
2.3.1-2~ubuntu16.04.15

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
2.3.1-2~ubuntu16.04.15

Open the chart page →

38,865
pact-brokerqamatic0.1.01 of 2See more

pact-broker qamatic 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.32.0-2062d6c710099
webrick@1.4.2
1.4.4

Open the chart page →

3,533
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
webrick@1.4.2
1.4.4
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
webrick@1.4.2
1.4.4

Open the chart page →

11,942
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1

Open the chart page →

18,197
quarks-jobquarks0.0.124-g03faac81 of 1See more

quarks-job quarks 0.0.124-g03faac8

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1

Open the chart page →

1,804
quarks-secretquarks0.0.677-ga060bb61 of 1See more

quarks-secret quarks 0.0.677-ga060bb6

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1

Open the chart page →

1,814
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1

Open the chart page →

4,010
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
webrick@1.4.2
1.4.4

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
webrick@1.4.2
1.4.4

Open the chart page →

20,462
coralogix-fluentdromholdings1.0.31 of 1See more

coralogix-fluentd romholdings 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.4.4

Open the chart page →

750
fluentdslamdev0.0.61 of 1See more

fluentd slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
webrick@1.4.2
1.4.4

Open the chart page →

1,384
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2020-25613.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
webrick@1.6.0
1.6.1

Open the chart page →

11,405

Container images carrying it

42 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
webrick@1.4.2
1.4.4
4
istio/examples-bookinfo-details-v1:1.14.04c3379923c8a
webrick@1.4.2
1.4.4
2
istio/examples-bookinfo-details-v1:1.15.0fce0bcbff0be
webrick@1.4.2
1.4.4
2
bryanalves/fluentd:0.5d3605be4b178
webrick@1.4.2
1.4.4
1
bryanalves/honeywell_exporter:0.0.1195f73dce8b21
webrick@1.4.2
1.4.4
1
bryanalves/smart_exporter:0.2af47dfbb9413
webrick@1.4.2
1.4.4
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
webrick@1.4.2
1.4.4
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
webrick@1.4.2
1.4.4
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
webrick@1.4.2
1.4.4
1
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
webrick@1.4.2
1.4.4
1
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
ruby2.3@2.3.3-1+deb9u4
2.3.3-1+deb9u9
1
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
webrick@1.4.2
1.4.4
1
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
webrick@1.4.2
1.4.4
1
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
webrick@1.4.2
1.4.4
1
gollumorg/gollum:latest7cd5305a3cf7
webrick@1.6.0
1.6.1
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
webrick@1.4.2
1.4.4
1
istio/examples-bookinfo-details-v1:1.17.02b081e3c86dd
webrick@1.6.0
1.6.1
1
klausmeyer/docker-registry-browser:1.3.5430a440d95af
webrick@1.6.0
1.6.1
1
kubesphere/examples-bookinfo-details-v1:1.13.0108d022f64f0
webrick@1.4.2
1.4.4
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
webrick@1.4.2
1.4.4
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
webrick@1.4.2
1.4.4
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
webrick@1.4.2
1.4.4
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
webrick@1.4.2
1.4.4
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
webrick@1.4.2
1.4.4
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
webrick@1.4.2
1.4.4
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ruby2.3@2.3.1-2~16.04.5
2.3.1-2~ubuntu16.04.15
1
omecproject/onos-progran:1.0.05715e5648aa0
ruby2.3@2.3.1-2~16.04.5
2.3.1-2~ubuntu16.04.15
1
pactfoundation/pact-broker:2.32.0-2062d6c710099
webrick@1.4.2
1.4.4
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
webrick@1.6.0
1.6.1
1
zammad/zammad-docker-compose:zammad-4.1.0-312808e2dfa810
webrick@1.4.2
1.4.4
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
webrick@1.4.2
ruby2.5@2.5.8-4.11.1
1.4.4
2.5.8-4.14.1
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
webrick@1.6.0
1.6.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
webrick@1.6.0
1.6.1
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
webrick@1.6.0
1.6.1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
webrick@1.6.0
1.6.1
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
webrick@1.6.0
1.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.