StackRadar

CVE-2020-28493

Medium

Advisory

Published 1 Feb 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.035
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
93
of 17,781 indexed, latest versions
Container images
102
deployed by those charts
Fix available
2 of 2
affected packages

Regular Expression Denial of Service (ReDoS) in Jinja2

Carried by container images the latest versions of 93 of 17,781 indexed charts deploy, on 102 images.

Affected packageAffected versionsFixed inImages
jinja2pypi2.7.2, 2.8, 2.8.1, 2.9.4+6 more2.11.3102
jinja2deb2.7.2-2, 2.10.1-22.7.2-2ubuntu0.1~esm2, 2.10.1-2ubuntu0.27
OSV records
GHSA-g3rq-g295-4j3mUBUNTU-CVE-2020-28493
Also known as
PYSEC-2021-66, SNYK-PYTHON-JINJA2-1012994, USN-6599-1

Charts affected

93 by stars
ChartLatestAffected imagesRadar Score
pgadminhalkeye1.0.01 of 1See more

pgadmin halkeye 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
chorss/docker-pgadmin4:4.115c549cacb8ab
jinja2@2.10.1
2.11.3

Open the chart page →

2,555
resurrectbothalkeye0.1.51 of 1See more

resurrectbot halkeye 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
halkeye/slack-resurrect:v0.1.477b05e95fdb5
jinja2@2.10.1
2.11.3

Open the chart page →

3,809
congson-charthelm-chart-example10.1.02 of 2See more

congson-chart helm-chart-example1 0.1.0

2 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
kunchalavikram/connectedcity:v14a559a47579e
jinja2@2.11.2
2.11.3
kunchalavikram/connectedfactory:v152c13fb9b1d9
jinja2@2.11.2
2.11.3

Open the chart page →

1,400
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
jinja2@2.11.2
2.11.3

Open the chart page →

4,422
prometheus-aws-costs-exporterhelm-charts-nr0.1.51 of 1See more

prometheus-aws-costs-exporter helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
jinja2@2.10
2.11.3

Open the chart page →

3,553
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
jinja2@2.10.3
2.11.3

Open the chart page →

3,314
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
jinja2@2.10
2.11.3

Open the chart page →

7,232
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
jinja2@2.10.1
2.11.3

Open the chart page →

18,980
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
jinja2@2.11.2
2.11.3

Open the chart page →

9,854
http-reqtracejulb-meVerified publisher1.0.41 of 1See more

http-reqtrace julb-me 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
julb/http-reqtrace:1.1.00806409af397
jinja2@2.11.2
2.11.3

Open the chart page →

1,854
kovi-appkovi-charts0.8.11 of 1See more

kovi-app kovi-charts 0.8.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
kennethreitz/httpbin:latest599fe5e50731
jinja2@2.10
2.11.3

Open the chart page →

14,813
specter-desktopkronkltdVerified publisher0.1.01 of 1See more

specter-desktop kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
lncm/specter-desktop:v0.10.4bca14d04397d
jinja2@2.11.2
2.11.3

Open the chart page →

1,850
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
jinja2@2.10.1
2.11.3

Open the chart page →

9,378
legendlegend0.1.21 of 1See more

legend legend 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
ghcr.io/grofers/legend:0.1d6e901ad0ebd
jinja2@2.10.1
2.11.3

Open the chart page →

4,067
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
lsstsqre/squash-api:0.5.34879415ec6ac
jinja2@2.11.2
2.11.3

Open the chart page →

6,611
webapp-colormarcusrepo0.1.11 of 1See more

webapp-color marcusrepo 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
kodekloud/webapp-color:latest99c3821ea49b
jinja2@2.10
2.11.3

Open the chart page →

911
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
jinja2@2.11.2
2.11.3

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
jinja2@2.11.2
2.11.3

Open the chart page →

43,341
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3

Open the chart page →

15,675
mtlsmtls0.3.41 of 1See more

mtls mtls 0.3.4

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
drgrove/mtls-server:v0.14.2361721759a2b
jinja2@2.10.1
2.11.3

Open the chart page →

1,458
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
elastichq/elasticsearch-hq:latestbb3bd22c2b87
jinja2@2.10.3
2.11.3

Open the chart page →

4,911
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jinja2@2.11.2
2.11.3

Open the chart page →

55,726
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3

Open the chart page →

22,658
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
jinja2@2.10.1
2.11.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
jinja2@2.10
2.11.3
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
jinja2@2.10
2.11.3

Open the chart page →

88,546
comac-platformopencord0.0.172 of 11See more

comac-platform opencord 0.0.17

2 of the 11 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
jinja2@2.10.1
2.11.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
jinja2@2.10
2.11.3

Open the chart page →

26,211
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
omecproject/mme-exporter:paging-latestbcc5f19fd676
jinja2@2.11.1
2.11.3

Open the chart page →

40,715
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
jinja2@2.8
2.11.3

Open the chart page →

12,609
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
jinja2@2.8
2.11.3
voltha/voltha-netconf:1.6.037f80524c207
jinja2@2.8
2.11.3
voltha/voltha-ofagent:1.6.09ee8c1f4428c
jinja2@2.8
2.11.3
voltha/voltha-voltha:1.6.0ff596b62de59
jinja2@2.8
2.11.3

Open the chart page →

93,855
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
openwhisk/kafkaprovider:2.1.063dc3d2a0904
jinja2@2.11.2
2.11.3
openwhisk/ow-utils:1.0.0c80dba0de3aa
jinja2@2.9.6
2.11.3

Open the chart page →

36,215
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
jinja2@2.11.1
2.11.3

Open the chart page →

11,151
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
jinja2@2.10
2.11.3

Open the chart page →

20,462
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
jinja2@2.9.4
2.11.3

Open the chart page →

11,422
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.14.022a0410f35a8
jinja2@2.10
2.11.3

Open the chart page →

20,462
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
jinja2@2.10.1
2.11.3

Open the chart page →

23,007
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
jinja2@2.9.6
2.11.3

Open the chart page →

10,967
classificationsignalen4.24.01 of 1See more

classification signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
jinja2@2.11.2
2.11.3

Open the chart page →

1,553
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
jinja2@2.10.1
2.11.3

Open the chart page →

2,060
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
jinja2@2.11.2
2.11.3

Open the chart page →

3,044
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
jinja2@2.11.2
2.11.3

Open the chart page →

1,779
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
jinja2@2.11.2
2.11.3

Open the chart page →

4,086
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
jinja2@2.10.1
2.11.3

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
jinja2@2.10.1
2.11.3

Open the chart page →

11,784

Container images carrying it

102 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
flagsmith/flagsmith-api:v2.6.0fd58556339a4
jinja2@2.11.2
2.11.3
1
galaxy/galaxy-init:v18.010267bad550e6
jinja2@2.7.2-2
jinja2@2.9.6
2.7.2-2ubuntu0.1~esm2
2.11.3
1
galaxy/galaxy-stable:v18.018e577a626dfd
jinja2@2.7.2-2
jinja2@2.7.2
2.7.2-2ubuntu0.1~esm2
2.11.3
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
jinja2@2.11.2
2.11.3
1
greenbirdit/locust:0.9.0e99d53bdc944
jinja2@2.10
2.11.3
1
halkeye/slack-resurrect:v0.1.477b05e95fdb5
jinja2@2.10.1
2.11.3
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
jinja2@2.11.2
2.11.3
1
jmferrer/azure-devops-agent:latest030f68ec6998
jinja2@2.10.1
2.11.3
1
julb/http-reqtrace:1.1.00806409af397
jinja2@2.11.2
2.11.3
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
jinja2@2.11.2
2.11.3
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
jinja2@2.11.2
2.11.3
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
jinja2@2.11.2
2.11.3
1
kennethreitz/httpbin:latest599fe5e50731
jinja2@2.10
2.11.3
1
kodekloud/webapp-color:latest99c3821ea49b
jinja2@2.10
2.11.3
1
kubesphere/examples-bookinfo-productpage-v1:1.13.0378f49ec9c44
jinja2@2.10.1
2.11.3
1
kunchalavikram/connectedcity:v14a559a47579e
jinja2@2.11.2
2.11.3
1
kunchalavikram/connectedfactory:v152c13fb9b1d9
jinja2@2.11.2
2.11.3
1
lncm/specter-desktop:v0.10.4bca14d04397d
jinja2@2.11.2
2.11.3
1
lsstsqre/squash-api:0.5.34879415ec6ac
jinja2@2.11.2
2.11.3
1
mediagis/nominatim:3.7c15e941485ef
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
jinja2@2.11.2
2.11.3
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
jinja2@2.10.1
2.11.3
1
neilpeterson/aks-helloworld:v1fb47732ef36b
jinja2@2.10
2.11.3
1
neilpeterson/chart-tweet:latest64fd8dab075f
jinja2@2.10
2.11.3
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
jinja2@2.11.2
2.11.3
1
octoprint/octoprint:1.4.0106c26efcd8a
jinja2@2.8.1
2.11.3
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
jinja2@2.11.1
2.11.3
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
jinja2@2.10
2.11.3
1
opendatacube/pipelines:wofs-1.225d810e8504b8
jinja2@2.10.1
2.11.3
1
opendatacube/restcube:latest91870111837c
jinja2@2.10.1
2.11.3
1
opendatacube/wms:latest1b90cdf68831
jinja2@2.10.1
2.11.3
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
jinja2@2.11.2
2.11.3
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
jinja2@2.9.6
2.11.3
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
jinja2@2.11.1
2.11.3
1
redash/redash:10.0.0.b503639392753c0376
jinja2@2.10.3
2.11.3
1
richardchesterwood/k8s-fleetman-webapp-angular:release2ed7d720878ac
jinja2@2.10
2.11.3
1
roadiehq/community-backstage-image:latestef355bf5b639
jinja2@2.10
2.11.3
1
samueldg/snappass:latest3987195edbe6
jinja2@2.10.3
2.11.3
1
seldonio/locust-core:0.81d0da98a2d76
jinja2@2.10.1
2.11.3
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
jinja2@2.11.2
2.11.3
1
statcan/ckan:2.93921305425b8
jinja2@2.10.1
2.11.3
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
jinja2@2.11.2
2.11.3
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
jinja2@2.10
2.11.3
1
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
jinja2@2.11.2
2.11.3
1
voltha/voltha-cli:1.6.0c4e41e92f046
jinja2@2.8
2.11.3
1
voltha/voltha-netconf:1.6.037f80524c207
jinja2@2.8
2.11.3
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
jinja2@2.8
2.11.3
1
voltha/voltha-tester:1.7.0655c3048a602
jinja2@2.8
2.11.3
1
voltha/voltha-voltha:1.6.0ff596b62de59
jinja2@2.8
2.11.3
1
wallabag/wallabag:2.4.25e4c26a7fb4a
jinja2@2.11.2
2.11.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.