StackRadar

CVE-2021-20291

Medium

Advisory

Published 10 May 2021In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,787 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

Improper Locking in github.com/containers/storage

Carried by container images the latest versions of 9 of 17,787 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/containers/storagegolangv0.0.0-20190726081758-912de200380a, v1.24.51.28.17
OSV records
GHSA-7qw8-847f-pggm
Also known as
GO-2021-0100

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1

Open the chart page →

6,696
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
github.com/containers/storage@v1.24.5
1.28.1

Open the chart page →

18,023
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/containers/storage@v1.24.5
1.28.1

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/containers/storage@v1.24.5
1.28.1

Open the chart page →

15,466
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1

Open the chart page →

15,290
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1

Open the chart page →

15,290
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1

Open the chart page →

11,437
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/containers/storage@v1.24.5
1.28.1

Open the chart page →

29,226
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-20291.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/containers/storage@v1.24.5
1.28.1

Open the chart page →

28,165

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/openshift/origin-cli:4.7464a3af4dfe0
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
github.com/containers/storage@v1.24.5
1.28.1
2
anchore/anchore-engine:v0.10.0bde9eedf639d
github.com/containers/storage@v1.24.5
1.28.1
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/containers/storage@v1.24.5
1.28.1
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1
1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/containers/storage@v0.0.0-20190726081758-912de200380a
1.28.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/containers/storage@v1.24.5
1.28.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.