StackRadar

CVE-2020-8285

High

Advisory

Published 9 Dec 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.098
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
264
of 17,781 indexed, latest versions
Container images
169
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 264 of 17,781 indexed charts deploy, on 169 images.

Affected packageAffected versionsFixed inImages
curlapk7.65.1-r0, 7.66.0-r0, 7.67.0-r0, 7.67.0-r1+2 more7.66.0-r3, 7.67.0-r3, 7.69.1-r391
curldeb7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16, 7.35.0-1ubuntu2.19+20 more7.35.0-1ubuntu2.20+esm6, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.478
OSV records
ALPINE-CVE-2020-8285UBUNTU-CVE-2020-8285
Also known as
USN-4665-1, USN-4665-2

Charts affected

264 by stars
ChartLatestAffected imagesRadar Score
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12

Open the chart page →

20,190
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

7,510
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.18

Open the chart page →

15,330
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

7,429
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12

Open the chart page →

20,190
alpinewenerme1.0.01 of 1See more

alpine wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
wener/base:3.12.0ef3bd19da190
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

1,263
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
curl@7.69.1-r1
7.69.1-r3

Open the chart page →

10,127
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.12

Open the chart page →

10,843
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
curl@7.67.0-r0
7.67.0-r3

Open the chart page →

3,424
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-8285.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

1,198

Container images carrying it

169 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.18
1
onosproject/onos:2.2.144914a8d4b3f
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
opendatacube/pipelines:wofs-1.225d810e8504b8
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.12
1
opendatacube/restcube:latest91870111837c
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
opendatacube/wms:latest1b90cdf68831
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
openwhisk/invoker:1.0.0f5831ec85525
curl@7.69.1-r1
7.69.1-r3
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.12
1
opsmx11/issuegen:v2.1.05c50ca123d88
curl@7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.20+esm6
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
curl@7.47.0-1ubuntu2.15
7.47.0-1ubuntu2.18
1
pnnlmiscscripts/anaconda:20200421-1700-nginx-1bbb6940d849f
curl@7.67.0-r0
7.67.0-r3
1
pnnlmiscscripts/k8s-node-image:1.14.10-nginx-78af4c559fff0
curl@7.67.0-r0
7.67.0-r3
1
pnnlmiscscripts/k8s-node-image:1.15.12-nginx-5d710d31000ce
curl@7.67.0-r1
7.67.0-r3
1
pozetroninc/keydb:v6.0.1653ae64f29da8
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.12
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.18
1
resouer/redis-slave:v2e2f198b49ba7
curl@7.35.0-1ubuntu2.3
7.35.0-1ubuntu2.20+esm6
1
runatlantis/atlantis:v0.16.145fbaf7e207c
curl@7.69.1-r0
7.69.1-r3
1
rundeck/rundeck:3.2.74d64fe56f767
curl@7.47.0-1ubuntu2.14
7.47.0-1ubuntu2.18
1
rundeck/rundeck:3.0.16b13e8059ad72
curl@7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.18
1
scrapinghub/splash:3.4.1a5f89bc84606
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
seldonio/locust-core:0.81d0da98a2d76
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.18
1
sismics/docs:v1.10f4b0ef019cf1
curl@7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.12
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.18
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.18
1
tpdock/freeradius:2.2.93da600c95a49
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.18
1
vectorim/riot-web:v1.7.8080e313abd37
curl@7.69.1-r0
7.69.1-r3
1
voltha/voltha-envoy:1.6.059ab2a00f712
curl@7.35.0-1ubuntu2.19
7.35.0-1ubuntu2.20+esm6
1
wavefronthq/proxy:9.2d1064d28f6eb
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.12
1
wener/base:3.12.0ef3bd19da190
curl@7.69.1-r0
7.69.1-r3
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.18
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.18
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.18
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.18
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
curl@7.67.0-r0
7.67.0-r3
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
curl@7.69.1-r1
7.69.1-r3
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
curl@7.69.1-r0
7.69.1-r3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.