StackRadar

CVE-2020-36567

High

Advisory

Published 14 Apr 2021In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
72nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
1 of 1
affected package

Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
github.com/gin-gonic/gingolangv1.4.0, v1.4.1-0.20190910091637-9aa870f108a1, v1.5.01.6.05
OSV records
GHSA-6vm3-jj99-7229
Also known as
GO-2020-0001

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-36567.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
github.com/gin-gonic/gin@v1.4.0
1.6.0

Open the chart page →

1,713
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-36567.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
github.com/gin-gonic/gin@v1.5.0
1.6.0

Open the chart page →

2,175
karmamesosphere1.3.01 of 1See more

karma mesosphere 1.3.0

1 of the 1 container images this version deploys carry CVE-2020-36567.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.503751e5eed656
github.com/gin-gonic/gin@v1.4.1-0.20190910091637-9aa870f108a1
1.6.0

Open the chart page →

2,111
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2020-36567.

Container imageDigestPackageFixed in
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
github.com/gin-gonic/gin@v1.5.0
1.6.0

Open the chart page →

68,284
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2020-36567.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
github.com/gin-gonic/gin@v1.4.0
1.6.0

Open the chart page →

4,158

Container images carrying it

5 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
lmierzwa/karma:v0.503751e5eed656
github.com/gin-gonic/gin@v1.4.1-0.20190910091637-9aa870f108a1
1.6.0
1
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
github.com/gin-gonic/gin@v1.5.0
1.6.0
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
github.com/gin-gonic/gin@v1.4.0
1.6.0
1
phntom/mindav:0.1.7-kix35695f546abbb
github.com/gin-gonic/gin@v1.4.0
1.6.0
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
github.com/gin-gonic/gin@v1.5.0
1.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.