StackRadar

CVE-2020-8911

Medium

Advisory

Published 11 Feb 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
896
of 17,790 indexed, latest versions
Container images
928
deployed by those charts
Fix available
1 of 1
affected package

CBC padding oracle issue in AWS S3 Crypto SDK for golang

Carried by container images the latest versions of 896 of 17,790 indexed charts deploy, on 928 images.

Affected packageAffected versionsFixed inImages
github.com/aws/aws-sdk-gogolangv1.12.54, v1.15.24, v1.17.7, v1.17.14+288 more1.34.0928
OSV records
GHSA-f5pg-7wfw-84q9GO-2022-0646

Charts affected

896 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

928 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gcr.io/kasten-images/prometheus:9.0.5da2bf307c353
github.com/aws/aws-sdk-go@v1.55.8
no fix listed
1
gcr.io/kasten-images/repositories:9.0.526a17e00ee25
github.com/aws/aws-sdk-go@v1.55.7
no fix listed
1
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
github.com/aws/aws-sdk-go@v1.55.7
no fix listed
1
gcr.io/kasten-images/state:9.0.54d01763016e9
github.com/aws/aws-sdk-go@v1.55.7
no fix listed
1
gcr.io/kasten-images/vbrintegrationapi:9.0.54a2438d399ff
github.com/aws/aws-sdk-go@v1.55.7
no fix listed
1
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhook873b968f02b5
github.com/aws/aws-sdk-go@v1.30.5
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator1e3db4f2eeed
github.com/aws/aws-sdk-go@v1.31.12
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activatora5de0fb75046
github.com/aws/aws-sdk-go@v1.29.34
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
github.com/aws/aws-sdk-go@v1.30.5
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
github.com/aws/aws-sdk-go@v1.31.12
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller30ce73388ae5
github.com/aws/aws-sdk-go@v1.30.5
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerb2cd45b8a8a4
github.com/aws/aws-sdk-go@v1.31.12
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
github.com/aws/aws-sdk-go@v1.31.12
1.34.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
github.com/aws/aws-sdk-go@v1.30.5
1.34.0
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
github.com/aws/aws-sdk-go@v1.50.8
no fix listed
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
github.com/aws/aws-sdk-go@v1.28.9
1.34.0
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
github.com/aws/aws-sdk-go@v1.44.153
no fix listed
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
github.com/aws/aws-sdk-go@v1.28.9
1.34.0
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
github.com/aws/aws-sdk-go@v1.50.8
no fix listed
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
github.com/aws/aws-sdk-go@v1.28.9
1.34.0
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
github.com/aws/aws-sdk-go@v1.28.9
1.34.0
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
github.com/aws/aws-sdk-go@v1.45.25
no fix listed
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
github.com/aws/aws-sdk-go@v1.42.50
no fix listed
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
github.com/aws/aws-sdk-go@v1.43.45
no fix listed
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
github.com/aws/aws-sdk-go@v1.49.6
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/aws/aws-sdk-go@v1.29.16
1.34.0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
github.com/aws/aws-sdk-go@v1.48.0
no fix listed
1
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
github.com/aws/aws-sdk-go@v1.55.5
no fix listed
1
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
github.com/aws/aws-sdk-go@v1.44.298
no fix listed
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
github.com/aws/aws-sdk-go@v1.51.17
no fix listed
1
ghcr.io/appscode/cluster-presets:v0.0.128fbdd2479645
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
github.com/aws/aws-sdk-go@v1.34.0
no fix listed
1
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
github.com/aws/aws-sdk-go@v1.54.18
no fix listed
1
ghcr.io/appscode/grafana:v2025.2.367d18880448c
github.com/aws/aws-sdk-go@v1.37.20
no fix listed
1
ghcr.io/appscode/inbox-agent:v0.0.66b99ee9feece
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/appscode/kube-ui-server:v0.7.079e67164b4f0
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/aws/aws-sdk-go@v1.44.273
no fix listed
1
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
github.com/aws/aws-sdk-go@v1.55.5
no fix listed
1
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
github.com/aws/aws-sdk-go@v1.44.122
no fix listed
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
github.com/aws/aws-sdk-go@v1.48.6
no fix listed
1
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
github.com/aws/aws-sdk-go@v1.55.8
no fix listed
1
ghcr.io/bank-vaults/vault-secrets-webhook:v1.23.198baf045a1c9
github.com/aws/aws-sdk-go@v1.55.8
no fix listed
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/aws/aws-sdk-go@v1.45.19
no fix listed
1
ghcr.io/bionicstork/bionicstork/relay:latest13290b9a64af
github.com/aws/aws-sdk-go@v1.55.7
no fix listed
1
ghcr.io/blind-oracle/cortex-tenant:v2.0.09f8896ffc15b
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
github.com/aws/aws-sdk-go@v1.55.6
no fix listed
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
github.com/aws/aws-sdk-go@v1.46.4
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.