StackRadar

CVE-2021-21290

Medium

Advisory

Published 8 Feb 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
151
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
1 of 2
affected packages

Local Information Disclosure Vulnerability in Netty on Unix-Like systems

Carried by container images the latest versions of 151 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
netty-codec-httpmaven4.0.27.Final, 4.0.52.Final, 4.1.12.Final, 4.1.13.Final+21 more4.1.59.Final113
nettymaven3.2.10.Final, 3.6.1.Final, 3.6.2.Final, 3.6.6.Final+6 moreno fix listed66
OSV records
GHSA-5mcr-gq6c-3hq2

Charts affected

151 by stars
ChartLatestAffected imagesRadar Score
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-21290.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
netty-codec-http@4.1.45.Final
4.1.59.Final

Open the chart page →

5,806

Container images carrying it

162 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
xetusoss/archiva:v2.2.588f25242b9ee
netty@3.6.6.Final
no fix listed
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
netty-codec-http@4.1.49.Final
4.1.59.Final
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
netty-codec-http@4.1.45.Final
4.1.59.Final
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
netty-codec-http@4.1.45.Final
4.1.59.Final
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
netty@3.10.6.Final
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
netty@3.10.6.Final
no fix listed
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
netty-codec-http@4.1.51.Final
4.1.59.Final
1
ghcr.io/kvaps/linstor-satellite:v1.14.0a573fb9bc809
netty-codec-http@4.1.51.Final
4.1.59.Final
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
netty@3.10.6.Final
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
netty@3.10.6.Final
no fix listed
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
netty@3.10.6.Final
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
netty@3.10.6.Final
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.