CVE-2021-22945
CriticalAdvisory
Published 23 Sept 2021In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.067
- 94th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 157
- of 17,781 indexed, latest versions
- Container images
- 154
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 157 of 17,781 indexed charts deploy, on 154 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 7.67.0-r0, 7.67.0-r1, 7.67.0-r3, 7.69.1-r0+8 more | 7.79.0-r0 | 154 |
- OSV records
- ALPINE-CVE-2021-22945
Charts affected
157 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| verzoektypecatalogusverzoektypecatalogus | 1.1.0 | 1 of 4See more | 7,429 |
| alpinewenerme | 1.0.0 | 1 of 1See more | 1,263 |
| athens-proxywenerme | 0.5.2 | 1 of 2See more | 4,984 |
| cadencewenerme | 0.23.0 | 1 of 5See more | 10,127 |
| sambawenerme | 1.0.0 | 1 of 1See more | 2,555 |
| apicurio-registry-sqlwitcom-gmbh | 0.1.0 | 1 of 1See more | 3,424 |
| rcloneymrs | 0.1.4 | 1 of 2See more | 1,198 |
Container images carrying it
154 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| buddy/ | 097c897f8b54 | curl | 7.79.0-r0 | 3 |
| library/ | 93baf2ec1bfe | curl | 7.79.0-r0 | 3 |
| nginxinc/ | 084242d8028c | curl | 7.79.0-r0 | 3 |
| xenondb/ | 0241a1112566 | curl | 7.79.0-r0 | 3 |
| apteno/ | 74035b864eed | curl | 7.79.0-r0 | 2 |
| giantswarm/ | 58a9d175cdb7 | curl | 7.79.0-r0 | 2 |
| governify/ | 2987672448c7 | curl | 7.79.0-r0 | 2 |
| jupyterhub/ | 8ced0a2f8073 | curl | 7.79.0-r0 | 2 |
| library/ | 07ab71a2c8e4 | curl | 7.79.0-r0 | 2 |
| minio/ | bf85c57cdfcc | curl | 7.79.0-r0 | 2 |
| statping/ | e874da513a5c | curl | 7.79.0-r0 | 2 |
| tkpd/ | 74441dadcfbd | curl | 7.79.0-r0 | 2 |
| absaoss/ | ad538a1285a0 | curl | 7.79.0-r0 | 1 |
| acockburn/ | 3a93281d7e94 | curl | 7.79.0-r0 | 1 |
| ajanvier/ | 91ac61b88c85 | curl | 7.79.0-r0 | 1 |
| alpine/ | a41efe02a041 | curl | 7.79.0-r0 | 1 |
| anapsix/ | 7cf7deb20399 | curl | 7.79.0-r0 | 1 |
| apache/ | 228eb0edf44b | curl | 7.79.0-r0 | 1 |
| apicurio/ | 44eeddd3562c | curl | 7.79.0-r0 | 1 |
| aquasec/ | 7ea4aa3d2eb6 | curl | 7.79.0-r0 | 1 |
| billimek/ | f14ccd7aad0e | curl | 7.79.0-r0 | 1 |
| conduction/ | 9cfeeb6c7c20 | curl | 7.79.0-r0 | 1 |
| conduction/ | c36094a41369 | curl | 7.79.0-r0 | 1 |
| conduction/ | ece1ab544c57 | curl | 7.79.0-r0 | 1 |
| conduction/ | 25415534d245 | curl | 7.79.0-r0 | 1 |
| conduction/ | 3423845692c1 | curl | 7.79.0-r0 | 1 |
| conduction/ | 2744565516e8 | curl | 7.79.0-r0 | 1 |
| conduction/ | e1d4ad1e22a8 | curl | 7.79.0-r0 | 1 |
| conduction/ | b6f95c8ead7d | curl | 7.79.0-r0 | 1 |
| conduction/ | 8f177f9f8a7b | curl | 7.79.0-r0 | 1 |
| conduction/ | 24f03c57568f | curl | 7.79.0-r0 | 1 |
| datawire/ | 07f8fe4f4f8e | curl | 7.79.0-r0 | 1 |
| datawire/ | 2beb65062c8b | curl | 7.79.0-r0 | 1 |
| datawire/ | 9716efbdd24b | curl | 7.79.0-r0 | 1 |
| denisshav/ | b97cc69fbac6 | curl | 7.79.0-r0 | 1 |
| devspacecloud/ | 9ccfe38b31b5 | curl | 7.79.0-r0 | 1 |
| devspacecloud/ | 49c397413f7b | curl | 7.79.0-r0 | 1 |
| factly/ | 24be158ec7d3 | curl | 7.79.0-r0 | 1 |
| felddy/ | 6c5d90b90349 | curl | 7.79.0-r0 | 1 |
| gitea/ | 85416d6f65fe | curl | 7.79.0-r0 | 1 |
| gitea/ | d5ab14cd29af | curl | 7.79.0-r0 | 1 |
| gitlab/ | fd7e5dfb9f30 | curl | 7.79.0-r0 | 1 |
| gmelillo/ | eeb2f9371b71 | curl | 7.79.0-r0 | 1 |
| gmelillo/ | 1b30f79cf7ea | curl | 7.79.0-r0 | 1 |
| gogs/ | 0195b095d0b2 | curl | 7.79.0-r0 | 1 |
| gogs/ | 420d53bb7277 | curl | 7.79.0-r0 | 1 |
| golenski/ | 48cfd60b8413 | curl | 7.79.0-r0 | 1 |
| gomods/ | d714c7ff0231 | curl | 7.79.0-r0 | 1 |
| gomods/ | efb811df7844 | curl | 7.79.0-r0 | 1 |
| graphiteapp/ | 04a0037cc2ae | curl | 7.79.0-r0 | 1 |