StackRadar

CVE-2020-28472

High

Advisory

Published 16 Nov 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
2 of 2
affected packages

Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
aws-sdknpm2.57.0, 2.171.0, 2.628.0, 2.667.0+2 more2.814.07
@aws-sdk/shared-ini-file-loadernpm0.1.0-preview.31.0.0-rc.91
OSV records
GHSA-rrc9-gqf8-8rwg

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
aws-sdk@2.778.0
2.814.0

Open the chart page →

5,946
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
aws-sdk@2.171.0
2.814.0

Open the chart page →

2,154
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
aws-sdk@2.738.0
2.814.0

Open the chart page →

10,994
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
aws-sdk@2.778.0
2.814.0

Open the chart page →

4,253
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
aws-sdk@2.57.0
2.814.0

Open the chart page →

4,614
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
aws-sdk@2.57.0
2.814.0

Open the chart page →

7,048
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
@aws-sdk/shared-ini-file-loader@0.1.0-preview.3
1.0.0-rc.9

Open the chart page →

6,524
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
aws-sdk@2.667.0
2.814.0

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
aws-sdk@2.667.0
2.814.0

Open the chart page →

29,220
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2020-28472.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
aws-sdk@2.628.0
2.814.0

Open the chart page →

2,838

Container images carrying it

8 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
migmartri/prerender:latest486aacfd5aa9
aws-sdk@2.57.0
2.814.0
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
aws-sdk@2.667.0
2.814.0
2
phntom/codimd:2.4.31b9aafbb62e6
@aws-sdk/shared-ini-file-loader@0.1.0-preview.3
1.0.0-rc.9
1
requarks/wiki:canary-2.5.2438b5865a7386c
aws-sdk@2.778.0
2.814.0
1
wiremind/scrapoxy:lateste7048929a676
aws-sdk@2.171.0
2.814.0
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
aws-sdk@2.628.0
2.814.0
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
aws-sdk@2.738.0
2.814.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
aws-sdk@2.778.0
2.814.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.