StackRadar

CVE-2023-1370

High

Advisory

Published 23 Mar 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
135
of 17,781 indexed, latest versions
Container images
151
deployed by those charts
Fix available
1 of 1
affected package

json-smart Uncontrolled Recursion vulnerability

Carried by container images the latest versions of 135 of 17,781 indexed charts deploy, on 151 images.

Affected packageAffected versionsFixed inImages
json-smartmaven1.1.1, 1.3.1, 1.3.2, 2.2.1+5 more2.4.9151
OSV records
GHSA-493p-pfq6-5258

Charts affected

135 by stars
ChartLatestAffected imagesRadar Score
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
aktosecurity/akto-api-protection:localbcd7382c9c1b
json-smart@2.4.7
2.4.9

Open the chart page →

11,285
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
json-smart@2.4.7
2.4.9

Open the chart page →

4,880
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
json-smart@2.3
2.4.9

Open the chart page →

5,277
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
json-smart@2.4.7
2.4.9

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
json-smart@2.4.7
2.4.9

Open the chart page →

16,975
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
json-smart@2.4.8
2.4.9

Open the chart page →

9,722
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
json-smart@2.3
2.4.9

Open the chart page →

5,806
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
json-smart@1.1.1
2.4.9

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
json-smart@1.1.1
2.4.9

Open the chart page →

6,497
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
json-smart@2.4.8
2.4.9

Open the chart page →

2,503
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
json-smart@2.3
2.4.9

Open the chart page →

16,860
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
json-smart@1.3.1
2.4.9
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
json-smart@1.3.1
2.4.9
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
json-smart@1.3.1
2.4.9
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
json-smart@1.3.1
2.4.9
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
json-smart@1.3.1
2.4.9
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
json-smart@1.3.1
2.4.9

Open the chart page →

58,857
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
json-smart@2.3
2.4.9

Open the chart page →

8,245
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
json-smart@1.3.2
2.4.9

Open the chart page →

10,564
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
json-smart@2.4.8
2.4.9

Open the chart page →

9,334
shenyuerdeng2.4.212 of 2See more

shenyu erdeng 2.4.21

2 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
json-smart@2.3
2.4.9
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
json-smart@2.3
2.4.9

Open the chart page →

12,513
scorpio-brokerfiware0.3.39 of 10See more

scorpio-broker fiware 0.3.3

9 of the 10 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
json-smart@2.4.7
2.4.9

Open the chart page →

55,600
scorpiobrokerfiware0.1.29 of 10See more

scorpiobroker fiware 0.1.2

9 of the 10 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
json-smart@2.4.7
2.4.9
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
json-smart@2.4.7
2.4.9

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
json-smart@2.4.7
2.4.9

Open the chart page →

5,286
mod-aesfolio-org0.1.331 of 1See more

mod-aes folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
folioci/mod-aes:latest6d67e9564270
json-smart@2.3
2.4.9

Open the chart page →

2,281
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
json-smart@2.4.7
2.4.9
gchq/hdfs:3.3.35ec58edbb2db
json-smart@2.4.7
2.4.9

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
json-smart@2.4.7
2.4.9

Open the chart page →

9,342
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
json-smart@2.3.1
2.4.9

Open the chart page →

12,581
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
json-smart@2.4.8
2.4.9
library/elasticsearch:7.17.1588c2ec10c7f2
json-smart@2.4.8
2.4.9

Open the chart page →

34,754
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
json-smart@1.3.2
2.4.9

Open the chart page →

4,556
siembolgresearch0.1.61 of 4See more

siembol gresearch 0.1.6

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
json-smart@2.4.8
2.4.9

Open the chart page →

14,312
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
json-smart@2.4.7
2.4.9

Open the chart page →

6,102
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
json-smart@1.3.2
2.4.9

Open the chart page →

10,540
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
json-smart@2.3
2.4.9

Open the chart page →

2,140
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
dannielkil/book-backend:lateste3b479a55a69
json-smart@2.4.8
2.4.9

Open the chart page →

9,122
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
json-smart@1.3.2
2.4.9

Open the chart page →

8,541
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
json-smart@2.4.7
2.4.9

Open the chart page →

7,144
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
json-smart@2.4.7
2.4.9

Open the chart page →

7,862
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
json-smart@1.3.1
2.4.9

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
json-smart@2.3
2.4.9
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
json-smart@1.1.1
2.4.9

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
json-smart@2.2.1
2.4.9
ibmcom/microclimate-portal:latested5505e5c7ec
json-smart@2.3
2.4.9
ibmcom/microclimate-theia:lateste17bdccc5030
json-smart@2.2.1
2.4.9

Open the chart page →

57,669
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
json-smart@1.1.1
2.4.9

Open the chart page →

19,295
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
json-smart@1.3.2
2.4.9

Open the chart page →

5,759
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
json-smart@2.3
2.4.9

Open the chart page →

6,174
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
json-smart@2.4.7
2.4.9

Open the chart page →

10,777
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
json-smart@1.3.2
2.4.9

Open the chart page →

5,759
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
json-smart@2.3
2.4.9

Open the chart page →

2,427
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
json-smart@2.3
2.4.9

Open the chart page →

7,929
elastictranscoderluiscajl0.46.03 of 4See more

elastictranscoder luiscajl 0.46.0

3 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
json-smart@1.3.2
2.4.9
elastictranscoder/media-storage:f6d861a026208b8c2359
json-smart@1.3.2
2.4.9
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
json-smart@2.4.7
2.4.9

Open the chart page →

58,160
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
json-smart@2.4.7
2.4.9

Open the chart page →

3,679
lavandaluiscajl0.0.1343 of 5See more

lavanda luiscajl 0.0.134

3 of the 5 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
json-smart@2.3
2.4.9
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
json-smart@2.3
2.4.9
lavandadelpatio/filebot:0.0.671f2ccec8c0d
json-smart@2.3
2.4.9

Open the chart page →

18,248
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
json-smart@2.3
2.4.9

Open the chart page →

15,855
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
json-smart@2.4.7
2.4.9

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
json-smart@2.4.7
2.4.9

Open the chart page →

10,603
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-1370.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
json-smart@1.3.2
2.4.9

Open the chart page →

2,141

Container images carrying it

151 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
json-smart@2.4.7
2.4.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.