StackRadar

CVE-2020-25638

High

Advisory

Published 9 Feb 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.029
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
1 of 1
affected package

SQL injection in hibernate-core

Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
hibernate-coremaven3.6.10.Final, 3.6.11.ONMS_RELEASE_1, 4.2.21.Final, 4.3.5.Final+13 more5.3.20.Final, 5.4.24.Final31
OSV records
GHSA-j8jw-g6fq-mp7h

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
gocdgocdOfficialVerified publisher2.18.11 of 2See more

gocd gocd 2.18.1

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
gocd/gocd-server:v26.1.0720d1012b93f
hibernate-core@3.6.10.Final
5.3.20.Final

Open the chart page →

1,362
spring-petclinic-cloudplatform9-communityVerified publisher0.2.03 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

3 of the 6 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
platform9community/customers-service:latest2089811e5cc6
hibernate-core@5.4.17.Final
5.4.24.Final
platform9community/vets-service:latestd1165c94dfb3
hibernate-core@5.4.17.Final
5.4.24.Final
platform9community/visits-service:latest8d11b50368c6
hibernate-core@5.4.17.Final
5.4.24.Final

Open the chart page →

41,872
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
hibernate-core@5.4.17.Final
5.4.24.Final

Open the chart page →

6,711
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
hibernate-core@4.2.21.Final
5.3.20.Final

Open the chart page →

4,679
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
torrespro/mca-worker:2.0.06d3bd305a1ba
hibernate-core@5.4.8.Final
5.4.24.Final

Open the chart page →

19,187
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
hibernate-core@5.4.8.Final
5.4.24.Final

Open the chart page →

19,745
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
hibernate-core@3.6.10.Final
5.3.20.Final

Open the chart page →

9,144
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
hibernate-core@5.1.13.Final
5.3.20.Final

Open the chart page →

23,665
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
hibernate-core@5.4.20.Final
5.4.24.Final

Open the chart page →

29,555
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
hibernate-core@5.1.17.Final
5.3.20.Final

Open the chart page →

19,802
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
hibernate-core@5.4.17.Final
5.4.24.Final

Open the chart page →

17,702
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
hibernate-core@3.6.10.Final
5.3.20.Final

Open the chart page →

27,949
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
hibernate-core@5.1.0.Final
5.3.20.Final

Open the chart page →

6,362
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
hibernate-core@5.2.17.Final
5.3.20.Final

Open the chart page →

6,451
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
hibernate-core@5.3.10.Final
5.3.20.Final

Open the chart page →

7,498
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
hibernate-core@5.4.18.Final
5.4.24.Final

Open the chart page →

10,264
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
hibernate-core@4.3.5.Final
5.3.20.Final

Open the chart page →

4,989
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
hibernate-core@3.6.11.ONMS_RELEASE_1
5.3.20.Final

Open the chart page →

2,024
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
andrianrf/bpjstk-service:latest46abe878d9d8
hibernate-core@5.4.21.Final
5.4.24.Final
andrianrf/bpjstk-simulator:latestb63fdb51d39d
hibernate-core@5.4.21.Final
5.4.24.Final
andrianrf/iso-client:latestba560086ce15
hibernate-core@5.4.21.Final
5.4.24.Final

Open the chart page →

34,671
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
hibernate-core@5.4.8.Final
5.4.24.Final

Open the chart page →

19,720
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
hibernate-core@5.4.18.Final
5.4.24.Final
reportportal/service-authorization:5.7.09e73114dbd15
hibernate-core@5.4.18.Final
5.4.24.Final

Open the chart page →

25,737
helm-chart-examplesalaboy0.1.01 of 1See more

helm-chart-example salaboy 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
hibernate-core@5.4.18.Final
5.4.24.Final

Open the chart page →

2,847
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
hibernate-core@5.3.2.Final
5.3.20.Final

Open the chart page →

13,605
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
hibernate-core@5.3.10.Final
5.3.20.Final

Open the chart page →

6,101
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
hibernate-core@5.1.2.Final
5.3.20.Final

Open the chart page →

8,554
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-25638.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
hibernate-core@5.4.22.Final
5.4.24.Final

Open the chart page →

3,424

Container images carrying it

31 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
andrianrf/bpjstk-service:latest46abe878d9d8
hibernate-core@5.4.21.Final
5.4.24.Final
1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
hibernate-core@5.4.21.Final
5.4.24.Final
1
andrianrf/iso-client:latestba560086ce15
hibernate-core@5.4.21.Final
5.4.24.Final
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
hibernate-core@5.4.22.Final
5.4.24.Final
1
atlassian/confluence-server:7.10.03b9222ab32ef
hibernate-core@5.3.2.Final
5.3.20.Final
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
hibernate-core@5.4.17.Final
5.4.24.Final
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
hibernate-core@5.4.8.Final
5.4.24.Final
1
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
hibernate-core@5.4.8.Final
5.4.24.Final
1
gocd/gocd-server:v19.3.02da45cb09d57
hibernate-core@3.6.10.Final
5.3.20.Final
1
gocd/gocd-server:v26.1.0720d1012b93f
hibernate-core@3.6.10.Final
5.3.20.Final
1
gridgain/community:8.9.11d32d182a0e6a
hibernate-core@4.2.21.Final
5.3.20.Final
1
just1not2/streama:1.10.48a2305192dec
hibernate-core@5.1.2.Final
5.3.20.Final
1
kimb88/hello-world-spring-boot:latest0639155241cb
hibernate-core@5.2.17.Final
5.3.20.Final
1
ncsa/datawolf:4.7.0af6649d59150
hibernate-core@4.3.5.Final
5.3.20.Final
1
openkm/openkm-ce:6.3.113bc465a7461b
hibernate-core@3.6.10.Final
5.3.20.Final
1
opennms/sentinel:36.0.288869082a14f
hibernate-core@3.6.11.ONMS_RELEASE_1
5.3.20.Final
1
platform9community/customers-service:latest2089811e5cc6
hibernate-core@5.4.17.Final
5.4.24.Final
1
platform9community/vets-service:latestd1165c94dfb3
hibernate-core@5.4.17.Final
5.4.24.Final
1
platform9community/visits-service:latest8d11b50368c6
hibernate-core@5.4.17.Final
5.4.24.Final
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
hibernate-core@5.1.0.Final
5.3.20.Final
1
refar/apm-api:v5.7.1241373fa2972
hibernate-core@5.4.18.Final
5.4.24.Final
1
reportportal/service-api:5.7.29df41f8fb320
hibernate-core@5.4.18.Final
5.4.24.Final
1
reportportal/service-authorization:5.7.09e73114dbd15
hibernate-core@5.4.18.Final
5.4.24.Final
1
robotshop/rs-shipping:latest89753ab48919
hibernate-core@5.4.20.Final
5.4.24.Final
1
rundeck/rundeck:3.2.74d64fe56f767
hibernate-core@5.1.17.Final
5.3.20.Final
1
rundeck/rundeck:3.0.16b13e8059ad72
hibernate-core@5.1.13.Final
5.3.20.Final
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
hibernate-core@5.4.18.Final
5.4.24.Final
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
hibernate-core@5.3.10.Final
5.3.20.Final
1
torrespro/mca-worker:2.0.06d3bd305a1ba
hibernate-core@5.4.8.Final
5.4.24.Final
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
hibernate-core@5.4.17.Final
5.4.24.Final
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
hibernate-core@5.3.10.Final
5.3.20.Final
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.