CVE-2020-8165
CriticalAdvisory
Published 26 May 2020In the index since 8 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.457
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4
- of 17,781 indexed, latest versions
- Container images
- 4
- deployed by those charts
- Fix available
- 1 of 1
- affected package
ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 4 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| activesupportgem | 5.2.0, 5.2.1, 5.2.2, 5.2.3 | 5.2.4.3 | 4 |
- OSV records
- GHSA-2p68-f74v-9wc6
Charts affected
4 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| honeywell-exporterbryanalves | 0.1.1 | 1 of 1See more | 5,437 |
| fluentd-cloudwatchcloudnativeapp | 0.9.0 | 1 of 2See more | 1,342 |
| fluentd-kubernetes-awscloudposse | 0.2.1 | 1 of 2See more | 1,305 |
| fluentd-papertrailmozilla | 0.2.2 | 1 of 1See more | 1,001 |
Container images carrying it
4 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bryanalves/ | 95f73dce8b21 | activesupport | 5.2.4.3 | 1 |
| fluent/ | 17398121d3cc | activesupport | 5.2.4.3 | 1 |
| fluent/ | 9c209835eea1 | activesupport | 5.2.4.3 | 1 |
| fluent/ | ce4885865850 | activesupport | 5.2.4.3 | 1 |