StackRadar

CVE-2020-27846

Critical

Advisory

Published 14 Apr 2021In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.049
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

XML Processing error in github.com/crewjam/saml

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
github.com/crewjam/samlgolangv0.0.0-20191031171751-c42136edf9b1, v0.3.0, v0.4.10.4.311
OSV records
GHSA-4hq8-gmxx-h6w9
Also known as
BIT-grafana-2020-27846, GO-2021-0058

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
kube-prometheuschoerodon9.3.11 of 7See more

kube-prometheus choerodon 9.3.1

1 of the 7 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

12,237
temporallemontechVerified publisher0.37.01 of 13See more

temporal lemontech 0.37.0

1 of the 13 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

14,893
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
github.com/crewjam/saml@v0.4.1
0.4.3

Open the chart page →

52,919
kube-prometheus-stackprometheus-worawutchan12.8.01 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

1 of the 6 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
github.com/crewjam/saml@v0.4.1
0.4.3

Open the chart page →

12,125
dnation-pingdnationcloud0.1.91 of 5See more

dnation-ping dnationcloud 0.1.9

1 of the 5 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
github.com/crewjam/saml@v0.4.1
0.4.3

Open the chart page →

10,454
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
github.com/crewjam/saml@v0.3.0
0.4.3

Open the chart page →

3,254
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

2,597
temporaldtrdnk-helm-chartsVerified publisher0.35.01 of 13See more

temporal dtrdnk-helm-charts 0.35.0

1 of the 13 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

20,205
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

3,191
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
github.com/crewjam/saml@v0.4.1
0.4.3

Open the chart page →

3,365
jx-app-flaggerjenkins-x0.0.51 of 2See more

jx-app-flagger jenkins-x 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

6,028
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

3,191
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:6.6.0052147d7e0ec
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

68,284
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

15,855
centralbrainsciencemeshVerified publisher0.0.31 of 5See more

centralbrain sciencemesh 0.0.3

1 of the 5 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
github.com/crewjam/saml@v0.4.1
0.4.3

Open the chart page →

9,754
seldon-core-analyticsseldon1.17.11 of 8See more

seldon-core-analytics seldon 1.17.1

1 of the 8 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

10,733
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

12,237
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

21,005
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

3,191
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-27846.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3

Open the chart page →

22,665

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:7.0.3d72946c8e5d5
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3
6
grafana/grafana:6.7.11ff3999e0fc0
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3
4
grafana/grafana:7.3.5511bc20bfcd1
github.com/crewjam/saml@v0.4.1
0.4.3
2
grafana/grafana:6.6.0052147d7e0ec
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3
1
grafana/grafana:7.3.315b977f5207d
github.com/crewjam/saml@v0.4.1
0.4.3
1
grafana/grafana:7.3.46d42886b3ebe
github.com/crewjam/saml@v0.4.1
0.4.3
1
grafana/grafana:7.2.1733842cca5bd
github.com/crewjam/saml@v0.4.1
0.4.3
1
grafana/grafana:6.5.1befcd84da2c1
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3
1
subspacecommunity/subspace:1.5.0e2042b63fb35
github.com/crewjam/saml@v0.3.0
0.4.3
1
surajwarbhe/grafana:v185248611e9f1
github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b1
0.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.