StackRadar

CVE-2020-7788

High

Advisory

Published 10 Dec 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.037
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
123
of 17,781 indexed, latest versions
Container images
122
deployed by those charts
Fix available
1 of 2
affected packages

ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

Carried by container images the latest versions of 123 of 17,781 indexed charts deploy, on 122 images.

Affected packageAffected versionsFixed inImages
ininpm1.0.0, 1.3.4, 1.3.51.3.6121
node-inideb1.1.0-1, 1.3.4-1, 1.3.5-1, 3.0.1-2no fix listed6
OSV records
GHSA-qqgx-2p2h-9c37UBUNTU-CVE-2020-7788
Also known as
SNYK-JS-INI-1048974

Charts affected

123 by stars
ChartLatestAffected imagesRadar Score
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
ini@1.3.5
1.3.6

Open the chart page →

109,294
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
ini@1.3.4
1.3.6
linuxserver/codimd:latestb801bbcf6386
ini@1.3.5
1.3.6

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
ini@1.3.4
1.3.6

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
ini@1.3.4
1.3.6

Open the chart page →

38,865
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
ini@1.3.5
1.3.6
openwhisk/ow-utils:1.0.0c80dba0de3aa
ini@1.3.4
node-ini@1.3.4-1
1.3.6
no fix listed

Open the chart page →

36,215
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
ini@1.3.5
1.3.6

Open the chart page →

1,986
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
ini@1.3.5
1.3.6
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ini@1.3.5
1.3.6

Open the chart page →

19,720
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
slagattollas/weatherservice-practica:latest68e7f56393fc
ini@1.3.5
1.3.6

Open the chart page →

28,484
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
ini@1.3.5
1.3.6

Open the chart page →

29,227
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
ini@1.3.5
1.3.6

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
ini@1.3.5
1.3.6

Open the chart page →

20,462
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ini@1.3.5
1.3.6

Open the chart page →

5,215
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ini@1.3.5
1.3.6

Open the chart page →

5,582
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
ini@1.3.4
1.3.6

Open the chart page →

3,638
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
ini@1.3.5
1.3.6

Open the chart page →

3,696
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ini@1.3.5
1.3.6

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ini@1.3.5
1.3.6

Open the chart page →

29,220
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ini@1.3.5
1.3.6

Open the chart page →

4,967
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
ini@1.3.5
node-ini@1.3.5-1
1.3.6
no fix listed

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
ini@1.3.5
1.3.6

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
ini@1.3.5
1.3.6

Open the chart page →

4,017
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
ini@1.3.5
1.3.6

Open the chart page →

2,838
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7788.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
ini@1.3.5
1.3.6

Open the chart page →

1,309

Container images carrying it

122 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ibmcom/app-nav-init:1.0.1240ff499eb5b
ini@1.3.4
1.3.6
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ini@1.3.4
1.3.6
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
ini@1.3.5
1.3.6
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
ini@1.3.5
1.3.6
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
ini@1.3.5
1.3.6
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ini@1.3.5
1.3.6
1
ibmcom/microclimate-portal:latested5505e5c7ec
ini@1.3.4
1.3.6
1
ibmcom/microclimate-theia:lateste17bdccc5030
ini@1.3.4
1.3.6
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ini@1.3.5
1.3.6
1
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
ini@1.3.5
1.3.6
1
jayfong/yapi:1.10.2163e5d621910
ini@1.3.5
1.3.6
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
ini@1.3.4
1.3.6
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ini@3.0.1-2
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
ini@1.3.5
1.3.6
1
konradkleine/docker-registry-frontend:v2181aad54ee64
ini@1.3.4
1.3.6
1
koumoul/capture:17108d47be3b2
ini@1.3.5
1.3.6
1
koumoul/openapi-viewer:18eeca2e8285b
ini@1.3.4
1.3.6
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
ini@1.3.5
1.3.6
1
lavandadelpatio/frontend:latest501c3f31e0bc
ini@1.3.5
1.3.6
1
linuxserver/cloud9:latest45c5fe102ff3
ini@1.3.4
1.3.6
1
linuxserver/code-server:4.10.1a5e43a05ae79
ini@1.0.0
1.3.6
1
linuxserver/codimd:latestb801bbcf6386
ini@1.3.5
1.3.6
1
logentries/docker-logentries:0.2.1f1f90a236998
ini@1.3.4
1.3.6
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
ini@1.3.5
node-ini@1.3.5-1
1.3.6
no fix listed
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
ini@1.3.4
1.3.6
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ini@1.3.5
1.3.6
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
ini@1.3.5
1.3.6
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
ini@1.3.4
1.3.6
1
minddocdev/hubot:0.1.96c60b11a4fa7
ini@1.3.5
1.3.6
1
mozilla/sentencecollector:2.0.91da6ff5c4895
ini@1.3.5
1.3.6
1
muluder/prograncontrollermcord:0.1.843b597a93da7
ini@1.3.4
1.3.6
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ini@1.3.5
1.3.6
1
nodered/node-red-docker:0.19.6-v8070643219ea2
ini@1.3.5
1.3.6
1
omecproject/onos-progran:1.0.05715e5648aa0
ini@1.3.4
1.3.6
1
ondrejsika/parking:latestb1fd497416c8
ini@1.3.5
1.3.6
1
openthread/otbr:latestf307f59f6432
ini@1.3.4
node-ini@1.3.4-1
1.3.6
no fix listed
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
ini@1.3.5
1.3.6
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
ini@1.3.4
node-ini@1.3.4-1
1.3.6
no fix listed
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
ini@1.3.5
1.3.6
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ini@1.3.5
1.3.6
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
ini@1.3.5
1.3.6
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
ini@1.3.5
1.3.6
1
polonel/trudesk:1.2.60cf6513f6fe3
ini@1.3.5
1.3.6
1
slagattollas/weatherservice-practica:latest68e7f56393fc
ini@1.3.5
1.3.6
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
ini@1.3.5
1.3.6
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
ini@1.3.5
node-ini@1.3.5-1
1.3.6
no fix listed
1
testhubio/testhub-frontend:on-preme86c2db53be8
ini@1.3.5
1.3.6
1
thelounge/thelounge:4.2.0-alpine639978459c3a
ini@1.3.5
1.3.6
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
ini@1.3.5
1.3.6
1
trufflesuite/ganache-cli:v6.12.2c062707f17f3
ini@1.3.5
1.3.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.