StackRadar

CVE-2020-35538

Medium

Advisory

Published 31 Aug 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
58
of 17,781 indexed, latest versions
Container images
61
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 58 of 17,781 indexed charts deploy, on 61 images.

Affected packageAffected versionsFixed inImages
libjpeg-turbodeb1.5.2-0ubuntu5.18.04.1, 1.5.2-0ubuntu5.18.04.3, 1.5.2-0ubuntu5.18.04.4, 2.0.3-0ubuntu1.20.04.11.5.2-0ubuntu5.18.04.6, 2.0.3-0ubuntu1.20.04.361
OSV records
UBUNTU-CVE-2020-35538
Also known as
USN-5631-1

Charts affected

58 by stars
ChartLatestAffected imagesRadar Score
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libjpeg-turbo@1.5.2-0ubuntu5.18.04.4
1.5.2-0ubuntu5.18.04.6
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libjpeg-turbo@1.5.2-0ubuntu5.18.04.4
1.5.2-0ubuntu5.18.04.6

Open the chart page →

14,536
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3

Open the chart page →

22,084
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3

Open the chart page →

9,167
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3

Open the chart page →

15,520
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3

Open the chart page →

30,687
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
libjpeg-turbo@1.5.2-0ubuntu5.18.04.4
1.5.2-0ubuntu5.18.04.6

Open the chart page →

14,493
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2020-35538.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3

Open the chart page →

28,605

Container images carrying it

61 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libjpeg-turbo@1.5.2-0ubuntu5.18.04.4
1.5.2-0ubuntu5.18.04.6
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libjpeg-turbo@2.0.3-0ubuntu1.20.04.1
2.0.3-0ubuntu1.20.04.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.