StackRadar

CVE-2021-21285

Medium

Advisory

Published 31 Jan 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

moby docker daemon crash during image pull of malicious image

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
github.com/moby/mobygolangv0.7.3-0.20190826074503-38ab9da00309, v1.4.2-0.20170731201646-1009e6a40b29, v1.13.1, v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible19.3.1517
OSV records
GHSA-6fj5-m822-rqx8

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15

Open the chart page →

4,154
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15

Open the chart page →

9,052
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15

Open the chart page →

1,301
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15

Open the chart page →

9,318
traefik-forward-authmesosphere0.3.101 of 2See more

traefik-forward-auth mesosphere 0.3.10

1 of the 2 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
github.com/moby/moby@v1.13.1
19.3.15

Open the chart page →

5,308
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
daprio/dashboard:0.14.07ba5d51e5b97
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15

Open the chart page →

28,131
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
github.com/moby/moby@v1.4.2-0.20170731201646-1009e6a40b29
19.3.15

Open the chart page →

2,220
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
fluxcd/source-controller:v0.10.031a8c79a6803
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15

Open the chart page →

7,705
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15

Open the chart page →

7,486
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15

Open the chart page →

14,673
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15

Open the chart page →

3,086
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
github.com/moby/moby@v1.13.1
19.3.15

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
github.com/moby/moby@v1.13.1
19.3.15

Open the chart page →

7,027
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15

Open the chart page →

8,902
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15

Open the chart page →

11,151
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2021-21285.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15

Open the chart page →

29,227

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/camel-k:1.10.43bb13d14f64a
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15
1
daprio/dashboard:0.15.04be696707bd1
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1
daprio/dashboard:0.14.07ba5d51e5b97
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15
1
fluxcd/helm-controller:v0.9.092b891e495d8
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1
fluxcd/source-controller:v0.10.031a8c79a6803
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1
istio/operator:1.12.06cfce8a071b9
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1
jmferrer/azure-devops-agent:latest030f68ec6998
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15
1
kiosksh/kiosk:0.2.11501725ba2025
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
github.com/moby/moby@v1.13.1
19.3.15
1
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
github.com/moby/moby@v1.13.1
19.3.15
1
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
github.com/moby/moby@v1.13.1
19.3.15
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15
1
sstarcher/helm-exporter:0.5.011769d01ba35
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
github.com/moby/moby@v1.4.2-0.20170731201646-1009e6a40b29
19.3.15
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
19.3.15
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
19.3.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.