StackRadar

CVE-2023-1370

High

Advisory

Published 23 Mar 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
135
of 17,781 indexed, latest versions
Container images
151
deployed by those charts
Fix available
1 of 1
affected package

json-smart Uncontrolled Recursion vulnerability

Carried by container images the latest versions of 135 of 17,781 indexed charts deploy, on 151 images.

Affected packageAffected versionsFixed inImages
json-smartmaven1.1.1, 1.3.1, 1.3.2, 2.2.1+5 more2.4.9151
OSV records
GHSA-493p-pfq6-5258

Charts affected

135 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
json-smart@2.4.2
2.4.9

Open the chart page →

6,556
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
json-smart@2.4.8
2.4.9

Open the chart page →

2,503
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
json-smart@1.3.2
2.4.9

Open the chart page →

3,812
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
json-smart@2.4.2
2.4.9

Open the chart page →

2,640
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
json-smart@2.4.7
2.4.9

Open the chart page →

5,357
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
json-smart@2.2.1
2.4.9

Open the chart page →

10,732
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
json-smart@2.3
2.4.9
dbanda/spark:2.4.6d0e6367876ae
json-smart@2.3
2.4.9

Open the chart page →

13,738
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
json-smart@1.3.2
2.4.9

Open the chart page →

12,111
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
json-smart@2.4.8
2.4.9

Open the chart page →

8,636
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
json-smart@1.3.2
2.4.9

Open the chart page →

7,930
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
json-smart@2.4.8
2.4.9

Open the chart page →

27,267
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
json-smart@1.3.2
2.4.9
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
json-smart@1.3.2
2.4.9

Open the chart page →

8,698
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
json-smart@2.3
2.4.9

Open the chart page →

7,166
hdfsdmwm-bigdataVerified publisher1.0.11 of 2See more

hdfs dmwm-bigdata 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gradiant/hdfs:3.2.2e3bf364fe713
json-smart@2.3
2.4.9

Open the chart page →

7,948
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
json-smart@2.3
2.4.9

Open the chart page →

7,335
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/elasticsearch:8.15.0310b9fc03b06
json-smart@2.4.8
2.4.9

Open the chart page →

13,521
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
json-smart@1.3.1
2.4.9

Open the chart page →

8,198
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.6.0f40a542832c4
json-smart@2.4.7
2.4.9

Open the chart page →

14,566
vrijbrpvrijbrpVerified publisher0.1.52 of 5See more

vrijbrp vrijbrp 0.1.5

2 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
vrijbrp/balie:developbc85c89530b9
json-smart@2.4.7
2.4.9
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
json-smart@2.4.8
2.4.9

Open the chart page →

8,811
soarv113assist-iot-cybersecurity-monitoring-soar0.1.32 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

2 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
json-smart@2.3
2.4.9
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
json-smart@2.4.7
2.4.9

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
json-smart@2.3
2.4.9

Open the chart page →

10,730
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
json-smart@2.3
2.4.9

Open the chart page →

4,532
hadoopcloudnativeapp1.1.01 of 1See more

hadoop cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
json-smart@1.1.1
2.4.9

Open the chart page →

5,772
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
json-smart@2.4.2
2.4.9

Open the chart page →

38,346
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
json-smart@2.3
2.4.9

Open the chart page →

2,140
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
json-smart@2.3
2.4.9

Open the chart page →

8,752
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
json-smart@2.3
2.4.9

Open the chart page →

6,531
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
json-smart@2.3
2.4.9

Open the chart page →

2,751
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
json-smart@2.3
2.4.9

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
json-smart@2.3
2.4.9

Open the chart page →

4,679
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
json-smart@2.4.2
2.4.9

Open the chart page →

17,284
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
json-smart@2.4.8
2.4.9

Open the chart page →

2,067
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
json-smart@1.3.2
2.4.9

Open the chart page →

12,019
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
json-smart@2.3
2.4.9

Open the chart page →

7,710
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
json-smart@2.4.7
2.4.9

Open the chart page →

13,479
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
json-smart@1.1.1
2.4.9

Open the chart page →

5,772
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
json-smart@2.4.8
2.4.9

Open the chart page →

37,373
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
json-smart@2.4.2
2.4.9

Open the chart page →

31,844
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
json-smart@2.3
2.4.9

Open the chart page →

4,621
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
json-smart@2.4.7
2.4.9

Open the chart page →

3,958
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
json-smart@2.4.8
2.4.9

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
json-smart@2.4.7
2.4.9

Open the chart page →

10,120
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
json-smart@1.3.2
2.4.9

Open the chart page →

6,045
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
json-smart@2.3
2.4.9

Open the chart page →

4,983
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
json-smart@2.2.1
2.4.9
seldonio/cluster-manager:0.2.729e362bb1ba2
json-smart@2.2.1
2.4.9

Open the chart page →

13,798
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
json-smart@2.4.8
2.4.9

Open the chart page →

13,486
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
json-smart@2.3
2.4.9

Open the chart page →

8,063
tocktock0.6.33 of 9See more

tock tock 0.6.3

3 of the 9 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
tock/bot_admin:25.10.7df3e38c77a38
json-smart@2.4.7
2.4.9
tock/bot_api:25.10.7dd5d5c70e333
json-smart@2.4.7
2.4.9
tock/kotlin_compiler:25.10.7c9c0fb40089a
json-smart@2.4.7
2.4.9

Open the chart page →

12,907
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
json-smart@1.3.2
2.4.9

Open the chart page →

7,835
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
json-smart@2.4.7
2.4.9

Open the chart page →

1,413

Container images carrying it

151 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-admin:2.4.2e8b7c4ddd069
json-smart@2.3
2.4.9
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
json-smart@2.3
2.4.9
3
gchq/hdfs:3.3.35ec58edbb2db
json-smart@2.4.7
2.4.9
3
mockserver/mockserver:5.15.0:mockserver-5.15.00f9ef78c9489
json-smart@2.4.7
2.4.9
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
json-smart@2.3
2.4.9
2
apache/druid:37.0.00116fb802786
json-smart@1.3.2
2.4.9
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
json-smart@2.3
2.4.9
2
danisla/hadoop:2.9.0255ba2dd739b
json-smart@1.1.1
2.4.9
2
dependencytrack/apiserver:4.6.3485ac0952c02
json-smart@2.4.8
2.4.9
2
hookiesolutions/webhookie:latest0629694246ba
json-smart@2.4.7
2.4.9
2
inaccel/coral:2.18c53744ed70b
json-smart@1.3.2
2.4.9
2
library/elasticsearch:7.17.35e6ac15bf6a5
json-smart@2.4.2
2.4.9
2
library/neo4j:4.3.2-enterprise56a9453c4064
json-smart@2.4.2
2.4.9
2
opensearchproject/opensearch:2.1.04254021a8c71
json-smart@2.4.7
2.4.9
2
opensearchproject/opensearch:1.1.0967d7f57f72f
json-smart@2.4.7
2.4.9
2
rodolpheche/wiremock:2.26.03be08a386092
json-smart@2.3
2.4.9
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
json-smart@2.4.7
2.4.9
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
json-smart@2.4.7
2.4.9
2
5200710/hadoop:3.2.3-java8092d3088a5fb
json-smart@1.3.2
2.4.9
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
json-smart@2.3
2.4.9
1
adityaprasadpathak/myapp:3.07e3b9777362c
json-smart@1.3.2
2.4.9
1
airbyte/cron:0.40.17caf4f551c546
json-smart@2.4.7
2.4.9
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
json-smart@2.4.7
2.4.9
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
json-smart@2.4.7
2.4.9
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
json-smart@2.3
2.4.9
1
apache/drill:1.21.11f96558fd292
json-smart@2.4.7
2.4.9
1
apache/druid:29.0.10cef139b6bf1
json-smart@1.3.2
2.4.9
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
json-smart@1.3.2
2.4.9
1
apache/hadoop:3af361b20bec0
json-smart@1.3.2
2.4.9
1
apache/iotdb:0.11.28647309f95d1
json-smart@2.3
2.4.9
1
apache/iotdb:0.13.3-nodeafa47bf1692a
json-smart@2.3
2.4.9
1
apache/nifi-registry:1.14.0090b7f87ec7f
json-smart@2.3
2.4.9
1
apache/nifi-registry:0.8.0974efa2f21da
json-smart@2.3
2.4.9
1
apachepinot/pinot:latest-jdk110018bb04ced7
json-smart@2.4.7
2.4.9
1
apache/shenyu-admin:2.5.1e2be712fc4f4
json-smart@2.4.8
2.4.9
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
json-smart@2.4.7
2.4.9
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
json-smart@2.3
2.4.9
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
json-smart@2.3
2.4.9
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
json-smart@2.4.7
2.4.9
1
atlassian/confluence-server:7.10.03b9222ab32ef
json-smart@2.3
2.4.9
1
atlassian/jira-software:8.14.037bc46cbec1a
json-smart@2.3
2.4.9
1
atlassian/jira-software:9.7.264a75aa4ec4e
json-smart@2.4.8
2.4.9
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
json-smart@2.4.8
2.4.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.