StackRadar

CVE-2021-20218

High

Advisory

Published 24 May 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Improper Limitation of a Pathname to a Restricted Directory in Fabric8 Kubernetes Client

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
kubernetes-clientmaven4.2.2, 4.3.0, 4.4.1, 4.4.2+4 more4.7.214
OSV records
GHSA-jwh2-ffg4-48xc

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
kubernetes-client@4.6.1
4.7.2
dbanda/spark:2.4.6d0e6367876ae
kubernetes-client@4.6.1
4.7.2

Open the chart page →

13,738
spring-petclinic-cloudplatform9-communityVerified publisher0.2.04 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

4 of the 6 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
platform9community/api-gateway:latest40a4970de568
kubernetes-client@4.4.1
4.7.2
platform9community/customers-service:latest2089811e5cc6
kubernetes-client@4.4.1
4.7.2
platform9community/vets-service:latestd1165c94dfb3
kubernetes-client@4.4.1
4.7.2
platform9community/visits-service:latest8d11b50368c6
kubernetes-client@4.4.1
4.7.2

Open the chart page →

41,872
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
kubernetes-client@4.6.0
4.7.2

Open the chart page →

8,752
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
kubernetes-client@4.2.2
4.7.2

Open the chart page →

3,958
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
kubernetes-client@4.4.2
4.7.2

Open the chart page →

6,147
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
kubernetes-client@4.4.2
4.7.2

Open the chart page →

6,147
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
kubernetes-client@4.2.2
4.7.2

Open the chart page →

26,356
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
kubernetes-client@4.3.0
4.7.2

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
kubernetes-client@4.7.1
4.7.2

Open the chart page →

41,044
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
kubernetes-client@4.4.2
4.7.2

Open the chart page →

36,215
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2021-20218.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
kubernetes-client@4.6.2
4.7.2

Open the chart page →

6,949

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gradiant/spark:2.4.4-python-alpine97657d56e927
kubernetes-client@4.4.2
4.7.2
2
dbanda/livy:0.80ca125e68e53
kubernetes-client@4.6.1
4.7.2
1
dbanda/spark:2.4.6d0e6367876ae
kubernetes-client@4.6.1
4.7.2
1
ladeit/ladeit:latest962b665ffe82
kubernetes-client@4.2.2
4.7.2
1
onosproject/onos:2.2.144914a8d4b3f
kubernetes-client@4.3.0
4.7.2
1
openwhisk/invoker:1.0.0f5831ec85525
kubernetes-client@4.4.2
4.7.2
1
platform9community/api-gateway:latest40a4970de568
kubernetes-client@4.4.1
4.7.2
1
platform9community/customers-service:latest2089811e5cc6
kubernetes-client@4.4.1
4.7.2
1
platform9community/vets-service:latestd1165c94dfb3
kubernetes-client@4.4.1
4.7.2
1
platform9community/visits-service:latest8d11b50368c6
kubernetes-client@4.4.1
4.7.2
1
remche/shinyproxy:2.6.18bcda8a04d3b
kubernetes-client@4.2.2
4.7.2
1
voltha/voltha-onos:5.1.8e038acb950d3
kubernetes-client@4.7.1
4.7.2
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
kubernetes-client@4.6.0
4.7.2
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
kubernetes-client@4.6.2
4.7.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.