StackRadar

CVE-2021-0341

High

Advisory

Published 24 May 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
103
of 17,781 indexed, latest versions
Container images
114
deployed by those charts
Fix available
1 of 1
affected package

Square OkHttp can accept the wrong certificate

Carried by container images the latest versions of 103 of 17,781 indexed charts deploy, on 114 images.

Affected packageAffected versionsFixed inImages
okhttpmaven3.3.1, 3.4.1, 3.4.2, 3.5.0+22 more4.9.2114
OSV records
GHSA-3cqm-mf7h-prrj
Also known as
A-171980069, ASB-A-171980069

Charts affected

103 by stars
ChartLatestAffected imagesRadar Score
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2021-0341.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
okhttp@3.14.9
4.9.2

Open the chart page →

12,455
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2021-0341.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
okhttp@3.13.1
4.9.2

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-0341.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
okhttp@3.9.0
4.9.2

Open the chart page →

28,605

Container images carrying it

114 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
voltha/voltha-onos:5.1.8e038acb950d3
okhttp@3.9.1
4.9.2
1
wavefronthq/proxy:9.2d1064d28f6eb
okhttp@3.8.1
4.9.2
1
wistefan/mvf:lateste0887302b2d8
okhttp@3.14.9
4.9.2
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
okhttp@3.14.6
4.9.2
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
okhttp@3.14.6
4.9.2
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
okhttp@3.12.12
4.9.2
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
okhttp@3.12.0
4.9.2
1
quay.io/apicurio/apicurio-registry-kube-sync:1.0.170ef31840269
okhttp@3.14.9
4.9.2
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
okhttp@3.14.9
4.9.2
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
okhttp@4.3.1
4.9.2
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
okhttp@3.9.0
4.9.2
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
okhttp@3.14.9
4.9.2
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
okhttp@3.14.9
4.9.2
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
okhttp@3.5.0
4.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.