StackRadar

CVE-2020-25658

Medium

Advisory

Published 12 Nov 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.017
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
87
of 17,781 indexed, latest versions
Container images
66
deployed by those charts
Fix available
1 of 2
affected packages

Timing attacks in python-rsa

Carried by container images the latest versions of 87 of 17,781 indexed charts deploy, on 66 images.

Affected packageAffected versionsFixed inImages
rsapypi3.4.2, 4.0, 4.5, 4.64.759
python-rsadeb3.4.2-1, 4.8-1no fix listed9
OSV records
DEBIAN-CVE-2020-25658GHSA-xrx6-fmxq-rjj2UBUNTU-CVE-2020-25658
Also known as
PYSEC-2020-100

Charts affected

87 by stars
ChartLatestAffected imagesRadar Score
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
rsa@4.6
4.7

Open the chart page →

4,086
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
rsa@4.6
4.7

Open the chart page →

4,918
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
rsa@4.6
4.7

Open the chart page →

5,173
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
rsa@4.0
4.7

Open the chart page →

5,851
kube-prometheuschoerodon9.3.11 of 7See more

kube-prometheus choerodon 9.3.1

1 of the 7 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
rsa@4.0
4.7

Open the chart page →

12,237
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
rsa@4.0
4.7
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
rsa@4.6
4.7

Open the chart page →

52,919
aws-ecr-credentialarchitectminds1.4.21 of 1See more

aws-ecr-credential architectminds 1.4.2

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
rsa@3.4.2
4.7

Open the chart page →

1,437
ecr-proxyevryfs-ossVerified publisher0.2.91 of 1See more

ecr-proxy evryfs-oss 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
rsa@3.4.2
4.7

Open the chart page →

1,523
redis-pod-labelerhmdmph1.0.21 of 1See more

redis-pod-labeler hmdmph 1.0.2

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
hmdmph/redis-pod-labeler:1.0.0-alpine7f1381fe0f3b
rsa@4.6
4.7

Open the chart page →

2,985
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
flagsmith/flagsmith-api:v2.6.0fd58556339a4
rsa@4.6
4.7

Open the chart page →

6,868
kube-prometheus-stackprometheus-worawutchan12.8.01 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

1 of the 6 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.1.03e86186656d3
rsa@4.6
4.7

Open the chart page →

12,125
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
rsa@4.6
4.7

Open the chart page →

4,568
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
rsa@4.6
4.7

Open the chart page →

7,984
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
rsa@3.4.2
4.7

Open the chart page →

8,752
jenkinsedu2.7.11 of 2See more

jenkins edu 2.7.1

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
rsa@4.6
4.7

Open the chart page →

4,423
octoprinthalkeye0.1.11 of 1See more

octoprint halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
octoprint/octoprint:1.4.0106c26efcd8a
rsa@4.6
4.7

Open the chart page →

3,608
mongo-pod-labelerhmdmph1.0.21 of 1See more

mongo-pod-labeler hmdmph 1.0.2

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
rsa@4.6
4.7

Open the chart page →

1,205
git-configmap-syncjulb-meVerified publisher1.0.11 of 2See more

git-configmap-sync julb-me 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
rsa@4.6
4.7

Open the chart page →

2,618
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
python-rsa@4.8-1
no fix listed

Open the chart page →

12,930
pghoardwiremindVerified publisher0.8.11 of 1See more

pghoard wiremind 0.8.1

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
wiremind/pghoard:12-2019-11-264dea42c8166c
rsa@3.4.2
4.7

Open the chart page →

2,952
backupalexanderbadel1.1.01 of 1See more

backup alexanderbadel 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
ghcr.io/alexanderbabel/database-s3-backup:1.3.33191b771a6f2
rsa@4.5
4.7

Open the chart page →

2,803
radosgwananace-chartsVerified publisher0.3.41 of 1See more

radosgw ananace-charts 0.3.4

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
ceph/daemon:latest-nautilus90f30824a96e
rsa@3.4.2
4.7

Open the chart page →

1,650
argocd-ecr-updaterargocd-ecr-updater4.1.01 of 1See more

argocd-ecr-updater argocd-ecr-updater 4.1.0

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
odaniait/aws-kubectl:latest3fff8a8570ec
rsa@3.4.2
4.7

Open the chart page →

1,511
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
python-rsa@4.8-1
no fix listed

Open the chart page →

32,501
aws-ecr-credentialaws-ecr-credentialVerified publisher1.5.21 of 1See more

aws-ecr-credential aws-ecr-credential 1.5.2

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
rsa@3.4.2
4.7

Open the chart page →

1,437
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
rsa@4.6
4.7

Open the chart page →

5,521
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
rsa@3.4.2
4.7

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
rsa@3.4.2
4.7

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
rsa@4.0
4.7

Open the chart page →

2,490
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
rsa@4.5
4.7

Open the chart page →

1,382
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
python-rsa@4.8-1
no fix listed

Open the chart page →

20,900
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
rsa@4.0
4.7

Open the chart page →

2,408
k8s-spot-termination-handlercloudnativeapp1.2.11 of 1See more

k8s-spot-termination-handler cloudnativeapp 1.2.1

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
rsa@3.4.2
4.7

Open the chart page →

2,095
prometheus-operatorcloudnativeapp6.4.01 of 7See more

prometheus-operator cloudnativeapp 6.4.0

1 of the 7 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
rsa@4.0
4.7

Open the chart page →

2,954
sentry-kubernetescloudnativeapp0.2.01 of 1See more

sentry-kubernetes cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
getsentry/sentry-kubernetes:latest6ac37974fd2a
rsa@4.0
4.7

Open the chart page →

1,415
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
rsa@4.0
4.7

Open the chart page →

5,060
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
rsa@3.4.2
4.7

Open the chart page →

70,895
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
python-rsa@3.4.2-1
rsa@3.4.2
no fix listed
4.7

Open the chart page →

27,728
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
python-rsa@3.4.2-1
rsa@3.4.2
no fix listed
4.7

Open the chart page →

24,335
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
rsa@4.6
4.7

Open the chart page →

4,422
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
rsa@3.4.2
4.7

Open the chart page →

10,466
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
rsa@3.4.2
4.7

Open the chart page →

10,466
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
python-rsa@4.8-1
no fix listed

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
python-rsa@4.8-1
no fix listed

Open the chart page →

30,699
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
rsa@4.0
4.7

Open the chart page →

5,055
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
rsa@4.6
4.7

Open the chart page →

4,422
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
rsa@4.6
4.7

Open the chart page →

7,984
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
rsa@4.5
4.7

Open the chart page →

3,999
gitlabkubesphereVerified publisher4.2.31 of 17See more

gitlab kubesphere 4.2.3

1 of the 17 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
rsa@4.6
4.7

Open the chart page →

38,133
online-boutiquekubesphere-testVerified publisher0.1.01 of 11See more

online-boutique kubesphere-test 0.1.0

1 of the 11 container images this version deploys carry CVE-2020-25658.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
rsa@4.6
4.7

Open the chart page →

26,018

Container images carrying it

66 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
rsa@4.0
4.7
11
oomk8s/readiness-check:2.0.07daa08b81954
rsa@3.4.2
4.7
6
argoproj/argocd:v1.8.1830e86cacefd
rsa@3.4.2
4.7
3
kiwigrid/k8s-sidecar:0.1.193170069ff0976
rsa@4.6
4.7
3
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
rsa@4.0
4.7
3
amancevice/superset:0.35.212a0a9e66550
rsa@4.0
4.7
2
architectminds/aws-kubectl:1.19735e59a1085
rsa@3.4.2
4.7
2
datawire/aes:1.14.48588eafe6862
rsa@4.6
4.7
2
larribas/mlflow:1.9.105ccb0b46bfb
rsa@4.6
4.7
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
rsa@4.0
4.7
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
rsa@4.0
4.7
2
weblate/weblate:4.2.2-169c160d37a3c
rsa@4.6
4.7
2
afrank/mozalert-controller:latestd463c37b08d7
rsa@4.6
4.7
1
amancevice/superset:0.28.1c8c04bfe3d66
rsa@4.0
4.7
1
bnjbvr/kresus:0.22.137e216b182c8
python-rsa@4.8-1
no fix listed
1
camptocamp/ekorre:0.1.035c91d5fda04
rsa@3.4.2
4.7
1
camptocamp/pghoard:10bff736b15623
rsa@3.4.2
4.7
1
ceph/daemon:latest-nautilus90f30824a96e
rsa@3.4.2
4.7
1
datadog/agent:7.22.08f20e56b5311
rsa@4.6
4.7
1
datadog/agent:6aad9994de6a7
rsa@4.5
4.7
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
rsa@4.6
4.7
1
datawire/aes:1.13.62beb65062c8b
rsa@4.6
4.7
1
datawire/emissary:2.0.2-ea9716efbdd24b
rsa@4.6
4.7
1
dysnix/pritunl:v1.29-r819951e3e7a32
rsa@4.0
4.7
1
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
rsa@3.4.2
4.7
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
rsa@4.6
4.7
1
galaxy/galaxy-init:v18.010267bad550e6
rsa@3.4.2
4.7
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
rsa@4.0
4.7
1
hmdmph/mongo-pod-labeler:1.0.1-alpine79e4a170f3dc
rsa@4.6
4.7
1
hmdmph/redis-pod-labeler:1.0.0-alpine7f1381fe0f3b
rsa@4.6
4.7
1
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
rsa@4.6
4.7
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
rsa@4.6
4.7
1
kiwigrid/k8s-sidecar:1.1.03e86186656d3
rsa@4.6
4.7
1
kiwigrid/k8s-sidecar:1.3.065095a82d4a1
rsa@4.6
4.7
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
rsa@4.0
4.7
1
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
rsa@4.0
4.7
1
kiwigrid/k8s-sidecar:0.1.20af151f677a63
rsa@4.0
4.7
1
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
rsa@3.4.2
4.7
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
rsa@4.6
4.7
1
mozilla/syncserver:latest016162bf39d8
rsa@4.5
4.7
1
nlmacamp/check_mk:latest5dbb8589f824
rsa@4.0
4.7
1
octoprint/octoprint:1.4.0106c26efcd8a
rsa@4.6
4.7
1
odaniait/aws-kubectl:latest3fff8a8570ec
rsa@3.4.2
4.7
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
rsa@4.0
4.7
1
opendatacube/restcube:latest91870111837c
python-rsa@3.4.2-1
rsa@3.4.2
no fix listed
4.7
1
opendatacube/wms:latest1b90cdf68831
python-rsa@3.4.2-1
rsa@3.4.2
no fix listed
4.7
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
rsa@4.0
4.7
1
softonic/gar-exporter:0.2.1a64d6c0e0ae5
rsa@4.6
4.7
1
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
rsa@4.0
4.7
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
python-rsa@4.8-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.