CVE-2021-21290
MediumAdvisory
Published 8 Feb 2021In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.2
- base score, highest
- EPSS
- 0.018
- 77th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 151
- of 17,781 indexed, latest versions
- Container images
- 162
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
Carried by container images the latest versions of 151 of 17,781 indexed charts deploy, on 162 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| netty-codec-httpmaven | 4.0.27.Final, 4.0.52.Final, 4.1.12.Final, 4.1.13.Final+21 more | 4.1.59.Final | 113 |
| nettymaven | 3.2.10.Final, 3.6.1.Final, 3.6.2.Final, 3.6.6.Final+6 more | no fix listed | 66 |
- OSV records
- GHSA-5mcr-gq6c-3hq2
Charts affected
151 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| opendistro-eswitcom-gmbh | 1.13.3 | 1 of 3See more | 5,806 |
Container images carrying it
162 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| xetusoss/ | 88f25242b9ee | netty | no fix listed | 1 |
| zammad/ | 8274d75a51fc | netty-codec-http | 4.1.59.Final | 1 |
| zbalogh/ | 7c247e399a1f | netty-codec-http | 4.1.59.Final | 1 |
| gcr.io/ | 0ee5f968d2ab | netty-codec-http | 4.1.59.Final | 1 |
| ghcr.io/ | ac62269785ac | netty | no fix listed | 1 |
| ghcr.io/ | 8caf5289fe73 | netty | no fix listed | 1 |
| ghcr.io/ | 00ce11c31087 | netty-codec-http | 4.1.59.Final | 1 |
| ghcr.io/ | a573fb9bc809 | netty-codec-http | 4.1.59.Final | 1 |
| ghcr.io/ | e949b0f733f0 | netty | no fix listed | 1 |
| ghcr.io/ | 8368359c8dd0 | netty | no fix listed | 1 |
| ghcr.io/ | b83b5b81d4b6 | netty | no fix listed | 1 |
| public.ecr.aws/ | 794b3bff9510 | netty | no fix listed | 1 |