StackRadar

CVE-2020-9296

Critical

Advisory

Published 10 Feb 2022In the index since 24 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1
of 17,837 indexed, latest versions
Container images
1
deployed by those charts
Fix available
1 of 1
affected package

Expression Language Injection in Netflix Conductor

Carried by container images the latest versions of 1 of 17,837 indexed charts deploy, on 1 image.

Affected packageAffected versionsFixed inImages
conductor-coremaven2.0.0-SNAPSHOT2.25.41
OSV records
GHSA-wfj5-2mqr-7jvv

Charts affected

1 by stars
ChartLatestAffected imagesRadar Score
frinx-machinefrinx-helm-charts11.0.01 of 26See more

frinx-machine frinx-helm-charts 11.0.0

1 of the 26 container images this version deploys carry CVE-2020-9296.

Container imageDigestPackageFixed in
frinx/conductor-server:6.1.159aa36c359f2
conductor-core@2.0.0-SNAPSHOT
2.25.4

Open the chart page →

43,343

Container images carrying it

1 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
frinx/conductor-server:6.1.159aa36c359f2
conductor-core@2.0.0-SNAPSHOT
2.25.4
1

syft 1.42.1 · advisories as of 24 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.