StackRadar

CVE-2020-27783

Medium

Advisory

Published 3 Dec 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
37
deployed by those charts
Fix available
2 of 2
affected packages

lxml vulnerable to Cross-site Scripting

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 37 images.

Affected packageAffected versionsFixed inImages
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+9 more4.6.237
lxmldeb4.3.2-14.3.2-1+deb10u11
OSV records
GHSA-pgww-xf46-h92rDSA-4810-1
Also known as
PYSEC-2020-62

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
4.6.2

Open the chart page →

10,732
rocketmqgin1.1.01 of 2See more

rocketmq gin 1.1.0

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
4.6.2

Open the chart page →

9,154
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
4.6.2

Open the chart page →

1,304
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
lxml@4.5.0
4.6.2

Open the chart page →

4,568
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
4.6.2

Open the chart page →

7,984
powerdnsadminhalkeye0.3.11 of 1See more

powerdnsadmin halkeye 0.3.1

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
lxml@4.5.2
4.6.2

Open the chart page →

3,345
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
lxml@4.4.1
4.6.2

Open the chart page →

5,104
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
lxml@4.4.2
4.6.2

Open the chart page →

24,930
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
4.6.2

Open the chart page →

2,018
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
4.6.2

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
lxml@3.6.4
4.6.2

Open the chart page →

923
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
4.6.2

Open the chart page →

70,895
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
cloudve/janis-terminal:latestaf56e77ca587
lxml@4.5.1
4.6.2

Open the chart page →

14,270
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
4.6.2

Open the chart page →

3,871
yadmscronce0.3.02 of 2See more

yadms cronce 0.3.0

2 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
4.6.2
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
4.6.2

Open the chart page →

2,500
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
lxml@4.2.1
4.6.2

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
4.6.2

Open the chart page →

18,863
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
4.6.2

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
lxml@4.2.1
4.6.2

Open the chart page →

24,335
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
4.6.2

Open the chart page →

3,978
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
4.6.2

Open the chart page →

7,984
heronheron0.20.5-incubating1 of 2See more

heron heron 0.20.5-incubating

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
4.6.2

Open the chart page →

1,449
ibm-business-automation-insights-devibm-charts3.2.03 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

3 of the 6 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
4.6.2
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
4.6.2
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
4.6.2

Open the chart page →

39,349
dynamo-dbk8s-home-lab-repo0.0.31 of 1See more

dynamo-db k8s-home-lab-repo 0.0.3

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
4.6.2

Open the chart page →

444
nacoskubesphere-testVerified publisher0.1.11 of 1See more

nacos kubesphere-test 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
4.6.2

Open the chart page →

4,153
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
lxml@4.2.5
4.6.2

Open the chart page →

55,726
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
lxml@3.6.4
4.6.2

Open the chart page →

12,609
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
lxml@3.6.4
4.6.2
voltha/voltha-netconf:1.6.037f80524c207
lxml@3.6.4
4.6.2
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lxml@3.6.4
4.6.2
voltha/voltha-voltha:1.6.0ff596b62de59
lxml@3.6.4
4.6.2

Open the chart page →

93,855
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
4.6.2

Open the chart page →

3,978
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
lxml@4.3.2-1
4.6.2
4.3.2-1+deb10u1

Open the chart page →

8,694
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
4.6.2

Open the chart page →

3,044
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
lxml@3.2.1
4.6.2

Open the chart page →

4,240
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.6.2

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2020-27783.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.6.2

Open the chart page →

11,784

Container images carrying it

37 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
4.6.2
2
weblate/weblate:4.2.2-169c160d37a3c
lxml@4.5.2
4.6.2
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.6.2
2
amazon/dynamodb-local:1.20.01ed00881c937
lxml@3.2.1
4.6.2
1
amazon/dynamodb-local:1.12.08414d80019b0
lxml@3.2.1
4.6.2
1
apache/bookkeeper:4.14.5a7d9970c148f
lxml@3.2.1
4.6.2
1
apache/hadoop:3af361b20bec0
lxml@3.2.1
4.6.2
1
apache/rocketmq:4.9.35ac2a4e0f627
lxml@3.2.1
4.6.2
1
bryanalves/sickrage:latest42f0a130001d
lxml@3.6.4
4.6.2
1
cloudve/janis-terminal:latestaf56e77ca587
lxml@4.5.1
4.6.2
1
datadog/agent:7.22.08f20e56b5311
lxml@4.5.0
4.6.2
1
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
4.6.2
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
4.6.2
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
4.6.2
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
4.6.2
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
4.6.2
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
4.6.2
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
4.6.2
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
4.6.2
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
4.6.2
1
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
4.6.2
1
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
4.6.2
1
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
4.6.2
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
lxml@4.4.1
4.6.2
1
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
4.6.2
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
lxml@4.2.5
4.6.2
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
lxml@4.5.2
4.6.2
1
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
4.6.2
1
opendatacube/restcube:latest91870111837c
lxml@4.2.1
4.6.2
1
opendatacube/wms:latest1b90cdf68831
lxml@4.2.1
4.6.2
1
statcan/ckan:2.93921305425b8
lxml@4.4.2
4.6.2
1
voltha/voltha-cli:1.6.0c4e41e92f046
lxml@3.6.4
4.6.2
1
voltha/voltha-netconf:1.6.037f80524c207
lxml@3.6.4
4.6.2
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lxml@3.6.4
4.6.2
1
voltha/voltha-tester:1.7.0655c3048a602
lxml@3.6.4
4.6.2
1
voltha/voltha-voltha:1.6.0ff596b62de59
lxml@3.6.4
4.6.2
1
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
lxml@4.3.2-1
4.6.2
4.3.2-1+deb10u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.