StackRadar

CVE-2020-36604

High

Advisory

Published 25 Sept 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
68
of 17,781 indexed, latest versions
Container images
63
deployed by those charts
Fix available
1 of 2
affected packages

hoek subject to prototype pollution via the clone function.

Carried by container images the latest versions of 68 of 17,781 indexed charts deploy, on 63 images.

Affected packageAffected versionsFixed inImages
hoeknpm0.4.2, 0.9.1, 2.16.3, 4.2.0+5 moreno fix listed63
@hapi/hoeknpm6.2.1, 6.2.48.5.12
OSV records
GHSA-c429-5p7v-vgjp

Charts affected

68 by stars
ChartLatestAffected imagesRadar Score
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
hoek@6.1.3
no fix listed

Open the chart page →

11,479
mojaloopmojaloop14.0.02 of 6See more

mojaloop mojaloop 14.0.0

2 of the 6 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
hoek@6.1.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
hoek@6.1.3
no fix listed

Open the chart page →

19,226
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
hoek@2.16.3
no fix listed
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
hoek@2.16.3
no fix listed

Open the chart page →

7,048
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
hoek@4.2.1
no fix listed

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
hoek@2.16.3
no fix listed

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
hoek@4.2.0
no fix listed

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
hoek@4.2.0
no fix listed

Open the chart page →

38,865
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
hoek@6.1.3
no fix listed

Open the chart page →

9,968
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
hoek@2.16.3
no fix listed

Open the chart page →

36,215
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
hoek@6.1.3
no fix listed

Open the chart page →

4,744
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
hoek@0.9.1
no fix listed

Open the chart page →

3,638
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
hoek@4.2.1
no fix listed

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
hoek@2.16.3
no fix listed

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
hoek@2.16.3
no fix listed

Open the chart page →

12,460
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
hoek@6.1.3
no fix listed

Open the chart page →

6,881
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
hoek@4.2.1
no fix listed

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
hoek@4.2.1
no fix listed

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-36604.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
hoek@4.2.1
no fix listed

Open the chart page →

5,806

Container images carrying it

63 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
hoek@2.16.3
no fix listed
1
ubercadence/web:v3.29.58564a5b44a6d
hoek@4.2.1
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
hoek@5.0.4
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
hoek@0.9.1
no fix listed
1
wiremind/scrapoxy:lateste7048929a676
hoek@4.2.1
no fix listed
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
hoek@2.16.3
no fix listed
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
hoek@2.16.3
no fix listed
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
hoek@2.16.3
no fix listed
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
hoek@2.16.3
no fix listed
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
hoek@6.1.3
no fix listed
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
hoek@2.16.3
no fix listed
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
hoek@4.2.1
no fix listed
1
quay.io/wekan/wekan:v5.65cb17600883a3
hoek@0.9.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.