CVE-2025-30754
MediumAdvisory
Published 15 Jul 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.8
- base score, highest
- EPSS
- 0.004
- 34th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 75
- of 17,781 indexed, latest versions
- Container images
- 66
- deployed by those charts
- Fix available
- 7 of 7
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 75 of 17,781 indexed charts deploy, on 66 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openjdk-8deb | 8u151-b12-0ubuntu0.16.04.2, 8u171-b11-0ubuntu0.16.04.1, 8u191-b12-2ubuntu0.16.04.1, 8u212-b03-0ubuntu1.18.04.1+11 more | 8u462-ga~us1-0ubuntu2~16.04.2, 8u462-ga~us1-0ubuntu2~18.04.2, 8u462-ga~us1-0ubuntu2~20.04.2, 8u462-ga~us1-0ubuntu2~22.04.2+1 more | 22 |
| javabitnami | 11.0.15-150, 11.0.18-10-1, 11.0.18-10-2, 11.0.20-8-3+12 more | 1.8.0 | 16 |
| openjdk-ltsdeb | 11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+6 more | 11.0.28+6-1ubuntu1~18.04.1, 11.0.28+6-1ubuntu1~20.04.1, 11.0.28+6-1ubuntu1~24.04.1 | 16 |
| openjdk-17deb | 17.0.3+7-0ubuntu0.20.04.1, 17.0.8+7-1~22.04, 17.0.9+9-1~20.04, 17.0.10+7-1~22.04.1+5 more | 17.0.16+8-1~deb12u1, 17.0.16+8~us1-0ubuntu1~20.04.6, 17.0.16+8~us1-0ubuntu1~22.04.1, 17.0.16+8~us1-0ubuntu1~24.04.1 | 10 |
| Javabitnami | 11.0.20-8, 11.0.21-10, 17.0.8-7, 17.0.10-13-1+2 more | 1.8.0 | 7 |
| openjdk-21deb | 21.0.5+11-1ubuntu1~24.04, 21.0.7+6~us1-0ubuntu1~24.04 | 21.0.8+9~us1-0ubuntu1~24.04.1 | 3 |
| jrebitnami | 17.0.16-12-0, 21.0.8-12-0 | 1.8.0 | 2 |
- OSV records
- BIT-java-2025-30754BIT-jre-2025-30754DEBIAN-CVE-2025-30754UBUNTU-CVE-2025-30754
- Also known as
- BIT-java-min-2025-30754, USN-7667-1, USN-7668-1, USN-7674-1, USN-7690-1
Charts affected
75 by stars
Container images carrying it
66 by charts deploying them
A fixed version is listed for 7 of the 7 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| sismics/ | f4b0ef019cf1 | openjdk-lts | 11.0.28+6-1ubuntu1~18.04.1 | 1 |
| socialmediamacroscope/ | 70fb11d4f531 | openjdk-8 | 8u462-ga~us1-0ubuntu2~20.04.2 | 1 |
| soldevelo/ | cfdc08c2f577 | jre | 1.8.0 | 1 |
| svtechnmaa/ | 6e368ace0977 | openjdk-lts | 11.0.28+6-1ubuntu1~20.04.1 | 1 |
| tensorflow/ | 1e3172090703 | openjdk-8 | 8u462-ga~us1-0ubuntu2~16.04.2 | 1 |
| wavefronthq/ | d1064d28f6eb | openjdk-lts | 11.0.28+6-1ubuntu1~18.04.1 | 1 |
| ghcr.io/ | b52ff07f9f0c | openjdk-8 | 8u462-ga~us1-0ubuntu2~18.04.2 | 1 |
| ghcr.io/ | dab685e668d9 | openjdk-21 | 21.0.8+9~us1-0ubuntu1~24.04.1 | 1 |
| ghcr.io/ | 4569cae83c70 | openjdk-21 | 21.0.8+9~us1-0ubuntu1~24.04.1 | 1 |
| ghcr.io/ | ef3670f7e0a8 | openjdk-lts | 11.0.28+6-1ubuntu1~20.04.1 | 1 |
| ghcr.io/ | baa4fa9549dc | openjdk-8 | 8u462-ga~us1-0ubuntu2~18.04.2 | 1 |
| ghcr.io/ | 8368359c8dd0 | openjdk-lts | 11.0.28+6-1ubuntu1~20.04.1 | 1 |
| ghcr.io/ | a56dfe91f5b1 | openjdk-17 openjdk-8 | 17.0.16+8~us1-0ubuntu1~22.04.1 8u462-ga~us1-0ubuntu2~22.04.2 | 1 |
| ghcr.io/ | 916746209ac5 | openjdk-17 openjdk-8 | 17.0.16+8~us1-0ubuntu1~22.04.1 8u462-ga~us1-0ubuntu2~22.04.2 | 1 |
| ghcr.io/ | 63873f3f698e | openjdk-17 | 17.0.16+8~us1-0ubuntu1~22.04.1 | 1 |
| quay.io/ | c6a934439421 | openjdk-8 | 8u462-ga~us1-0ubuntu2~16.04.2 | 1 |