StackRadar

CVE-2020-28928

Medium

Advisory

Published 24 Nov 2020In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
410
of 17,787 indexed, latest versions
Container images
368
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 410 of 17,787 indexed charts deploy, on 368 images.

Affected packageAffected versionsFixed inImages
muslapk1.1.20-r3, 1.1.20-r4, 1.1.20-r5, 1.1.22-r2+6 more1.1.20-r6, 1.1.22-r4, 1.1.24-r3, 1.1.24-r10368
OSV records
ALPINE-CVE-2020-28928

Charts affected

410 by stars
ChartLatestAffected imagesRadar Score
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
musl@1.1.24-r8
1.1.24-r10

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
curlimages/curl:7.68.099a8e9629b3a
musl@1.1.22-r3
1.1.22-r4

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

3,369
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
musl@1.1.22-r3
1.1.22-r4

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
musl@1.1.22-r3
1.1.22-r4

Open the chart page →

2,791
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

966
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
musl@1.1.24-r2
1.1.24-r3

Open the chart page →

3,424
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
landoop/kafka-connect-ui:0.9.738d9d628cd88
musl@1.1.20-r3
1.1.20-r6

Open the chart page →

2,506
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
musl@1.1.24-r8
1.1.24-r10

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-28928.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
musl@1.1.24-r8
1.1.24-r10

Open the chart page →

3,023

Container images carrying it

368 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
musl@1.1.24-r2
1.1.24-r3
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
musl@1.1.20-r4
1.1.20-r6
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
musl@1.1.20-r4
1.1.20-r6
1
public.ecr.aws/jtekt-corporation/ecr-pullsecret-renewer:latest442cc3b32935
musl@1.1.24-r8
1.1.24-r10
1
quay.io/apicurio/apicurio-registry-kube-sync:1.0.170ef31840269
musl@1.1.24-r2
1.1.24-r3
1
quay.io/eclipse/che-devfile-registry:nightly5d25d47d6e17
musl@1.1.24-r9
1.1.24-r10
1
quay.io/fairwinds/clamav:v0.0.3e12bdddaa81d
musl@1.1.24-r0
1.1.24-r3
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
musl@1.1.22-r3
1.1.22-r4
1
quay.io/kube-ops/loki:2.2.14fbd63194674
musl@1.1.20-r5
1.1.20-r6
1
quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.32.0251e733bf41c
musl@1.1.24-r2
1.1.24-r3
1
quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.30.0b312c91d0de6
musl@1.1.24-r0
1.1.24-r3
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
musl@1.1.20-r5
1.1.20-r6
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
musl@1.1.24-r2
1.1.24-r3
1
quay.io/opsmxpublic/oes-pre-configure:v29b052fbb046f
musl@1.1.24-r8
1.1.24-r10
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
musl@1.1.24-r9
1.1.24-r10
1
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
musl@1.1.24-r8
1.1.24-r10
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
musl@1.1.24-r2
1.1.24-r3
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
musl@1.1.20-r5
1.1.20-r6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.