StackRadar

CVE-2020-9488

Low

Advisory

Published 5 Jun 2020In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.081
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
43
of 17,781 indexed, latest versions
Container images
39
deployed by those charts
Fix available
1 of 1
affected package

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender

Carried by container images the latest versions of 43 of 17,781 indexed charts deploy, on 39 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+6 more2.12.3, 2.13.239
OSV records
GHSA-vwqq-5vrc-xw9h

Charts affected

43 by stars
ChartLatestAffected imagesRadar Score
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
log4j-core@2.12.1
2.12.3

Open the chart page →

3,229
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
log4j-core@2.11.1
2.12.3

Open the chart page →

4,099
flinkriskfocus0.2.01 of 1See more

flink riskfocus 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-core@2.12.1
2.12.3

Open the chart page →

3,235
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
log4j-core@2.11.1
2.12.3
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
log4j-core@2.11.1
2.12.3

Open the chart page →

8,698
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.3
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j-core@2.6.2
2.12.3

Open the chart page →

20,837
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
log4j-core@2.9.0
2.12.3

Open the chart page →

18,042
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
log4j-core@2.6.2
2.12.3

Open the chart page →

8,198
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
log4j-core@2.11.1
2.12.3

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
log4j-core@2.13.0
2.13.2

Open the chart page →

10,730
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
log4j-core@2.8.2
2.12.3

Open the chart page →

4,532
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
log4j-core@2.11.0
2.12.3

Open the chart page →

7,891
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
log4j-core@2.11.1
2.12.3

Open the chart page →

6,110
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.3

Open the chart page →

6,882
elasticsearch-dataempathyco0.2.01 of 2See more

elasticsearch-data empathyco 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
log4j-core@2.11.1
2.12.3

Open the chart page →

3,703
elasticsearch-masterempathyco0.3.01 of 2See more

elasticsearch-master empathyco 0.3.0

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
log4j-core@2.11.1
2.12.3

Open the chart page →

3,703
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
log4j-core@2.11.0
2.12.3

Open the chart page →

4,983
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
log4j-core@2.9.1
2.12.3

Open the chart page →

8,063
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.12.3

Open the chart page →

15,970
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.13.2

Open the chart page →

5,806
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
log4j-core@2.11.1
2.12.3

Open the chart page →

22,442
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
log4j-core@2.10.0
2.12.3
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j-core@2.10.0
2.12.3

Open the chart page →

16,860
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
log4j-core@2.11.1
2.12.3

Open the chart page →

8,245
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.12.3

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.12.3

Open the chart page →

55,600
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
log4j-core@2.10.0
2.12.3

Open the chart page →

6,988
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.3
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j-core@2.6.2
2.12.3

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.3

Open the chart page →

6,882
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
ibmcom/app-nav-was-controller:1.0.1a6748792da26
log4j-core@2.11.2
2.12.3

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
log4j-core@2.11.1
2.12.3
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
log4j-core@2.11.1
2.12.3

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
log4j-core@2.8.2
2.12.3

Open the chart page →

57,669
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
log4j-core@2.11.1
2.12.3

Open the chart page →

7,929
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j-core@2.10.0
2.12.3

Open the chart page →

15,855
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.13.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.13.2

Open the chart page →

10,603
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
2.13.2

Open the chart page →

12,927
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
log4j-core@2.8.2
2.12.3

Open the chart page →

9,606
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.12.3

Open the chart page →

6,907
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.12.3

Open the chart page →

3,164
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-core@2.9.1
2.12.3

Open the chart page →

11,841
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.3

Open the chart page →

4,538
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.3

Open the chart page →

5,460
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.13.2

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2020-9488.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
2.12.3

Open the chart page →

6,213

Container images carrying it

39 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.3
4
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.13.2
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j-core@2.10.0
2.12.3
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
log4j-core@2.11.1
2.12.3
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j-core@2.6.2
2.12.3
2
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.13.2
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.12.3
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
log4j-core@2.11.1
2.12.3
1
apacheignite/ignite:2.7.0d7deab68b8fa
log4j-core@2.11.0
2.12.3
1
apachepulsar/pulsar:2.6.14db6ff0b4045
log4j-core@2.10.0
2.12.3
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
log4j-core@2.9.0
2.12.3
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
log4j-core@2.13.0
2.13.2
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
log4j-core@2.11.1
2.12.3
1
datappeal/hive-metastore:lateste38c085a3567
log4j-core@2.8.2
2.12.3
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
log4j-core@2.11.1
2.12.3
1
folioci/mod-marccat:latest1b57d690d568
log4j-core@2.10.0
2.12.3
1
fonoster/routr:1.0.0-rc52ca65af17cbc
log4j-core@2.11.0
2.12.3
1
graylog2/server:2.4.3-38ff28c66e6c1
log4j-core@2.9.1
2.12.3
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
log4j-core@2.11.2
2.12.3
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
log4j-core@2.11.1
2.12.3
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
log4j-core@2.11.1
2.12.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
log4j-core@2.8.2
2.12.3
1
jacobalberty/unifi:5.10.19c409924e2463
log4j-core@2.11.1
2.12.3
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-core@2.12.1
2.12.3
1
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-core@2.9.1
2.12.3
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
log4j-core@2.11.1
2.12.3
1
library/sonarqube:8.9.2-community88cd63154d4b
log4j-core@2.11.1
2.12.3
1
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.3
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
log4j-core@2.11.1
2.12.3
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
2.12.3
1
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
2.13.2
1
openzipkin/zipkin:2.21.060c3970df479
log4j-core@2.12.1
2.12.3
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.3
1
pedrocesarti/jmeter-docker:3.314851f144f57
log4j-core@2.8.2
2.12.3
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
log4j-core@2.6.2
2.12.3
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.12.3
1
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.12.3
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
log4j-core@2.11.1
2.12.3
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.12.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.