StackRadar

CVE-2020-28498

Medium

Advisory

Published 8 Mar 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.012
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
25
of 17,781 indexed, latest versions
Container images
24
deployed by those charts
Fix available
1 of 1
affected package

Elliptic Uses a Broken or Risky Cryptographic Algorithm

Carried by container images the latest versions of 25 of 17,781 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
ellipticnpm6.4.0, 6.4.1, 6.5.0, 6.5.2+1 more6.5.424
OSV records
GHSA-r9p9-mrjm-926w

Charts affected

25 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
elliptic@6.4.1
6.5.4

Open the chart page →

10,732
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
elliptic@6.5.3
6.5.4

Open the chart page →

5,251
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
elliptic@6.4.1
6.5.4

Open the chart page →

9,261
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
elliptic@6.4.1
6.5.4

Open the chart page →

6,868
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
elliptic@6.5.3
6.5.4

Open the chart page →

3,444
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
elliptic@6.4.1
6.5.4

Open the chart page →

5,300
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
elliptic@6.5.2
6.5.4

Open the chart page →

7,517
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
elliptic@6.4.1
6.5.4

Open the chart page →

25,443
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
elliptic@6.4.1
6.5.4

Open the chart page →

29,901
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
elliptic@6.5.3
6.5.4

Open the chart page →

25,456
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
elliptic@6.5.2
6.5.4

Open the chart page →

11,174
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
elliptic@6.4.1
6.5.4

Open the chart page →

3,005
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
elliptic@6.5.3
6.5.4

Open the chart page →

3,260
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
elliptic@6.4.0
6.5.4

Open the chart page →

5,941
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
elliptic@6.5.0
6.5.4

Open the chart page →

32,915
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
elliptic@6.5.3
6.5.4

Open the chart page →

4,944
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
elliptic@6.4.0
6.5.4

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
elliptic@6.5.2
6.5.4

Open the chart page →

3,651
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
elliptic@6.5.3
6.5.4

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
elliptic@6.5.2
6.5.4

Open the chart page →

6,684
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
elliptic@6.5.3
6.5.4

Open the chart page →

27,465
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
elliptic@6.5.2
6.5.4

Open the chart page →

5,215
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
elliptic@6.5.2
6.5.4

Open the chart page →

3,696
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
elliptic@6.5.3
6.5.4

Open the chart page →

2,460
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-28498.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
elliptic@6.5.3
6.5.4

Open the chart page →

10,127

Container images carrying it

24 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gradiant/open5gs-webui:2.7.5fbd10c017541
elliptic@6.4.1
6.5.4
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
elliptic@6.4.0
6.5.4
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
elliptic@6.5.2
6.5.4
1
daskdev/dask-notebook:1.1.0052630f5ca04
elliptic@6.4.1
6.5.4
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
elliptic@6.5.3
6.5.4
1
ethersphere/bzz-token-service:latest7624f11a72ad
elliptic@6.5.3
6.5.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
elliptic@6.4.1
6.5.4
1
gristlabs/grist:0.7.96e71b1914a7e
elliptic@6.5.2
6.5.4
1
henrywhitaker3/speedtest-tracker:latest47159a940229
elliptic@6.5.3
6.5.4
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
elliptic@6.5.0
6.5.4
1
lavandadelpatio/frontend:latest501c3f31e0bc
elliptic@6.5.2
6.5.4
1
linuxserver/codimd:latestb801bbcf6386
elliptic@6.5.3
6.5.4
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
elliptic@6.4.1
6.5.4
1
misskey/misskey:12.110.1e08b7c478093
elliptic@6.5.3
6.5.4
1
mozilla/sentencecollector:2.0.91da6ff5c4895
elliptic@6.5.2
6.5.4
1
ondrejsika/parking:latestb1fd497416c8
elliptic@6.5.2
6.5.4
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
elliptic@6.4.1
6.5.4
1
testhubio/testhub-frontend:on-preme86c2db53be8
elliptic@6.5.2
6.5.4
1
ubercadence/web:v3.29.58564a5b44a6d
elliptic@6.5.3
6.5.4
1
wekanteam/wekan:v4.2268a51f0327df
elliptic@6.4.0
6.5.4
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
elliptic@6.5.3
6.5.4
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
elliptic@6.5.3
6.5.4
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
elliptic@6.5.3
6.5.4
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
elliptic@6.4.1
6.5.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.