StackRadar

CVE-2020-28493

Medium

Advisory

Published 1 Feb 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.035
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
93
of 17,781 indexed, latest versions
Container images
102
deployed by those charts
Fix available
2 of 2
affected packages

Regular Expression Denial of Service (ReDoS) in Jinja2

Carried by container images the latest versions of 93 of 17,781 indexed charts deploy, on 102 images.

Affected packageAffected versionsFixed inImages
jinja2pypi2.7.2, 2.8, 2.8.1, 2.9.4+6 more2.11.3102
jinja2deb2.7.2-2, 2.10.1-22.7.2-2ubuntu0.1~esm2, 2.10.1-2ubuntu0.27
OSV records
GHSA-g3rq-g295-4j3mUBUNTU-CVE-2020-28493
Also known as
PYSEC-2021-66, SNYK-PYTHON-JINJA2-1012994, USN-6599-1

Charts affected

93 by stars
ChartLatestAffected imagesRadar Score
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3

Open the chart page →

32,259
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
jinja2@2.11.2
2.11.3

Open the chart page →

4,086
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
jinja2@2.11.2
2.11.3

Open the chart page →

4,918
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
jinja2@2.11.2
2.11.3

Open the chart page →

5,173
supersetcloudposse1.2.01 of 1See more

superset cloudposse 1.2.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
jinja2@2.10.1
2.11.3

Open the chart page →

5,851
fadicetic0.3.13 of 25See more

fadi cetic 0.3.1

3 of the 25 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
amancevice/superset:0.35.212a0a9e66550
jinja2@2.10.1
2.11.3
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
jinja2@2.11.2
2.11.3
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
jinja2@2.11.2
2.11.3

Open the chart page →

52,919
ansible-semaphoreansible-semaphore0.1.01 of 1See more

ansible-semaphore ansible-semaphore 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
jinja2@2.11.2
2.11.3

Open the chart page →

4,019
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
flagsmith/flagsmith-api:v2.6.0fd58556339a4
jinja2@2.11.2
2.11.3

Open the chart page →

6,868
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
jinja2@2.10
2.11.3

Open the chart page →

36,094
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
jinja2@2.10.3
2.11.3

Open the chart page →

38,346
pgadmin4folio-org1.2.301 of 1See more

pgadmin4 folio-org 1.2.30

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.22b1f00b8163cf
jinja2@2.11.2
2.11.3

Open the chart page →

2,034
kube-ops-viewgeek-cookbookVerified publisher1.2.21 of 1See more

kube-ops-view geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
jinja2@2.11.2
2.11.3

Open the chart page →

1,848
octoprinthalkeye0.1.11 of 1See more

octoprint halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
octoprint/octoprint:1.4.0106c26efcd8a
jinja2@2.8.1
2.11.3

Open the chart page →

3,608
powerdnsadminhalkeye0.3.11 of 1See more

powerdnsadmin halkeye 0.3.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
jinja2@2.11.2
2.11.3

Open the chart page →

3,345
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
jinja2@2.10.1
2.11.3

Open the chart page →

5,104
smarter-demosmarterOfficialVerified publisher0.1.51 of 7See more

smarter-demo smarter 0.1.5

1 of the 7 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3

Open the chart page →

45,832
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
jinja2@2.10.1
2.11.3

Open the chart page →

24,930
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
jinja2@2.11.2
2.11.3

Open the chart page →

12,007
radosgwananace-chartsVerified publisher0.3.41 of 1See more

radosgw ananace-charts 0.3.4

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
ceph/daemon:latest-nautilus90f30824a96e
jinja2@2.7.2
2.11.3

Open the chart page →

1,650
snappassappuio1.0.01 of 3See more

snappass appuio 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
samueldg/snappass:latest3987195edbe6
jinja2@2.10.3
2.11.3

Open the chart page →

1,488
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
jinja2@2.11.2
2.11.3

Open the chart page →

5,521
aks-helloworldazure-sample0.1.11 of 1See more

aks-helloworld azure-sample 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
neilpeterson/aks-helloworld:v1fb47732ef36b
jinja2@2.10
2.11.3

Open the chart page →

4,269
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
jinja2@2.10
2.11.3

Open the chart page →

5,224
azure-vote-osbaazure-sample0.1.01 of 1See more

azure-vote-osba azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
jinja2@2.10
2.11.3

Open the chart page →

4,269
twitter-sentimentazure-sample0.1.01 of 3See more

twitter-sentiment azure-sample 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
neilpeterson/chart-tweet:latest64fd8dab075f
jinja2@2.10
2.11.3

Open the chart page →

11,833
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
jinja2@2.10.1
2.11.3

Open the chart page →

18,980
puppetboardbootcVerified publisher0.1.41 of 1See more

puppetboard bootc 0.1.4

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
bootc/puppetboard:1.1.0f1383295e7be
jinja2@2.11.1
2.11.3

Open the chart page →

1,292
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
jinja2@2.11.1
2.11.3

Open the chart page →

3,891
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
jinja2@2.9.6
2.11.3

Open the chart page →

12,018
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
jinja2@2.10
2.11.3
daskdev/dask-notebook:1.1.0052630f5ca04
jinja2@2.10
2.11.3

Open the chart page →

29,901
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
jinja2@2.10
2.11.3

Open the chart page →

36,094
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
jinja2@2.10
2.11.3

Open the chart page →

1,352
supersetcloudnativeapp1.1.61 of 1See more

superset cloudnativeapp 1.1.6

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
amancevice/superset:0.28.1c8c04bfe3d66
jinja2@2.10
2.11.3

Open the chart page →

5,060
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
jinja2@2.7.2-2
jinja2@2.9.6
2.7.2-2ubuntu0.1~esm2
2.11.3
galaxy/galaxy-stable:v18.018e577a626dfd
jinja2@2.7.2-2
jinja2@2.7.2
2.7.2-2ubuntu0.1~esm2
2.11.3

Open the chart page →

70,895
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
jinja2@2.10
2.11.3

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jinja2@2.11.2
2.11.3
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
jinja2@2.11.2
2.11.3
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jinja2@2.11.2
2.11.3
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jinja2@2.11.2
2.11.3
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jinja2@2.11.2
2.11.3
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jinja2@2.11.2
2.11.3
confluentinc/cp-zookeeper:6.1.078c190f4472c
jinja2@2.11.2
2.11.3

Open the chart page →

58,857
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
jinja2@2.10.1
2.11.3

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
jinja2@2.11.2
2.11.3

Open the chart page →

18,863
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
opendatacube/pipelines:wofs-1.225d810e8504b8
jinja2@2.10.1
2.11.3

Open the chart page →

22,405
restcubedatacube-charts0.2.91 of 1See more

restcube datacube-charts 0.2.9

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
opendatacube/restcube:latest91870111837c
jinja2@2.10.1
2.11.3

Open the chart page →

24,335
kube-web-viewdecayofmind0.0.41 of 1See more

kube-web-view decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
jinja2@2.11.2
2.11.3

Open the chart page →

2,264
mlflowdeliveryheroVerified publisher1.0.101 of 1See more

mlflow deliveryhero 1.0.10

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
jinja2@2.11.2
2.11.3

Open the chart page →

4,422
prometheus-aws-costs-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-aws-costs-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
jinja2@2.10
2.11.3

Open the chart page →

3,553
amundsenduyet1.1.03 of 7See more

amundsen duyet 1.1.0

3 of the 7 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
jinja2@2.11.1
2.11.3
amundsendev/amundsen-metadata:2.5.44d98eb21f5f9
jinja2@2.11.2
2.11.3
amundsendev/amundsen-search:2.4.099dda9502c3e
jinja2@2.11.2
2.11.3

Open the chart page →

11,174
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
jinja2@2.10.1
2.11.3

Open the chart page →

5,055
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
jinja2@2.10.1
2.11.3

Open the chart page →

14,673
bae-activation-servicefiware0.1.21 of 1See more

bae-activation-service fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
fiware/bae-activation-service:v0.0.33e3ec88d59ed
jinja2@2.11.2
2.11.3

Open the chart page →

3,186
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-webapp-angular:release2ed7d720878ac
jinja2@2.10
2.11.3

Open the chart page →

24,296
kube-ops-viewfluent-operatorVerified publisher0.1.21 of 1See more

kube-ops-view fluent-operator 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
hjacobs/kube-ops-view:20.4.058221b57d4d2
jinja2@2.11.2
2.11.3

Open the chart page →

1,848
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2020-28493.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
jinja2@2.11.2
2.11.3

Open the chart page →

4,358

Container images carrying it

102 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/grofers/legend:0.1d6e901ad0ebd
jinja2@2.10.1
2.11.3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
jinja2@2.10.1-2
jinja2@2.10.1
2.10.1-2ubuntu0.2
2.11.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.