StackRadar

CVE-2020-28928

Medium

Advisory

Published 24 Nov 2020In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
411
of 17,781 indexed, latest versions
Container images
368
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 411 of 17,781 indexed charts deploy, on 368 images.

Affected packageAffected versionsFixed inImages
muslapk1.1.20-r3, 1.1.20-r4, 1.1.20-r5, 1.1.22-r2+6 more1.1.20-r6, 1.1.22-r4, 1.1.24-r3, 1.1.24-r10368
OSV records
ALPINE-CVE-2020-28928

Charts affected

411 by stars
ChartLatestAffected imagesRadar Score
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

4,984
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
musl@1.1.24-r8
1.1.24-r10

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
curlimages/curl:7.68.099a8e9629b3a
musl@1.1.22-r3
1.1.22-r4

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

3,369
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
musl@1.1.22-r3
1.1.22-r4

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
musl@1.1.22-r3
1.1.22-r4

Open the chart page →

2,791
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

966
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

3,424
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
landoop/kafka-connect-ui:0.9.738d9d628cd88
musl@1.1.20-r3
1.1.20-r6

Open the chart page →

2,506
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
musl@1.1.24-r8
1.1.24-r10

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
musl@1.1.24-r8
1.1.24-r10

Open the chart page →

3,023

Container images carrying it

368 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
stakater/whitelister:v0.0.1639107924063e
musl@1.1.20-r5
1.1.20-r6
1
stakater/xposer:v0.0.2082b839b4517d
musl@1.1.20-r5
1.1.20-r6
1
subspacecommunity/subspace:1.5.0e2042b63fb35
musl@1.1.24-r2
1.1.24-r3
1
swaggerapi/swagger-ui:v3.24.3d434cac93813
musl@1.1.22-r3
1.1.22-r4
1
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
musl@1.1.24-r2
1.1.24-r3
1
t3nde/ssh-jump:latest7cc268408e1a
musl@1.1.24-r8
1.1.24-r10
1
tenstartups/ser2sock:latest379d9338c720
musl@1.1.20-r3
1.1.20-r6
1
testhubio/testhub-frontend:on-preme86c2db53be8
musl@1.1.24-r2
1.1.24-r3
1
thelounge/thelounge:4.2.0-alpine639978459c3a
musl@1.1.24-r2
1.1.24-r3
1
tobiasbp/db-backup:0.0.314bee6e33a26
musl@1.1.24-r9
1.1.24-r10
1
vectorim/riot-web:v1.7.8080e313abd37
musl@1.1.24-r8
1.1.24-r10
1
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
musl@1.1.24-r0
1.1.24-r3
1
voltha/voltha-adapter-simulated-olt:2.2.358b74386e276
musl@1.1.20-r4
1.1.20-r6
1
voltha/voltha-adapter-simulated-onu:2.2.3f04ebe2bc2e7
musl@1.1.20-r4
1.1.20-r6
1
voltha/voltha-ponsim:1.7.099b0278f8411
musl@1.1.22-r2
1.1.22-r4
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
musl@1.1.20-r5
1.1.20-r6
1
weaveworks/flagger:1.0.0-rc.5174307de1b36
musl@1.1.24-r2
1.1.24-r3
1
weaveworks/flagger:0.19.0a9c2e9df4227
musl@1.1.22-r3
1.1.22-r4
1
wener/base:3.12.0ef3bd19da190
musl@1.1.24-r8
1.1.24-r10
1
xetusoss/archiva:v2.2.588f25242b9ee
musl@1.1.20-r4
1.1.20-r6
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
musl@1.1.24-r0
1.1.24-r3
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
musl@1.1.24-r8
1.1.24-r10
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
musl@1.1.24-r2
1.1.24-r3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.