StackRadar

CVE-2021-23017

High

Advisory

Published 25 May 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.535
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nginx:1.18 security update

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe1:1.18.0-3.module+el8.4.0+11152+f736ed63.11
nginxapk1.16.0-r1, 1.16.1-r1, 1.18.0-r0, 1.18.0-r1+1 more1.16.1-r3, 1.18.0-r2, 1.18.0-r148
nginxdeb1.4.6-1ubuntu3.8ppa1, 1.10.3-1+deb9u3, 1.14.2-2+deb10u1, 1.14.2-2+deb10u31.4.6-1ubuntu3.9+esm2, 1.10.3-1+deb9u6, 1.14.2-2+deb10u44
OSV records
ALPINE-CVE-2021-23017RHSA-2021:2259UBUNTU-CVE-2021-23017DLA-2670-1DSA-4921-1
Also known as
RHSA-2021:2290, RHSA-2022:0323, USN-4967-2

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
openzipkin/zipkin-ui:2.21.0672cbc94256b
nginx@1.16.1-r1
1.16.1-r3

Open the chart page →

3,229
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
nginx@1.18.0-r0
1.18.0-r2

Open the chart page →

30,326
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
nginx@1.14.2-2+deb10u3
1.14.2-2+deb10u4

Open the chart page →

7,984
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
nginx@1.10.3-1+deb9u3
1.10.3-1+deb9u6

Open the chart page →

5,104
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
ajanvier/polr:2.3.091ac61b88c85
nginx@1.18.0-r13
1.18.0-r14

Open the chart page →

5,904
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nginx@1:1.14.1-9.module+el8.0.0+4108+af250afe
1:1.18.0-3.module+el8.4.0+11152+f736ed63.1

Open the chart page →

25,151
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
galaxy/galaxy-stable:v18.018e577a626dfd
nginx@1.4.6-1ubuntu3.8ppa1
1.4.6-1ubuntu3.9+esm2

Open the chart page →

70,895
handbrakegeek-cookbookVerified publisher0.1.21 of 1See more

handbrake geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
jlesage/handbrake:v1.24.25fa191e3c7ee
nginx@1.18.0-r1
1.18.0-r2

Open the chart page →

1,469
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
nginx@1.18.0-r1
1.18.0-r2

Open the chart page →

4,358
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
nginx@1.14.2-2+deb10u3
1.14.2-2+deb10u4

Open the chart page →

7,984
landing-pagelsst-sqre0.3.01 of 1See more

landing-page lsst-sqre 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
lsstsqre/lsp-landing-page:latest4653f18b5418
nginx@1.16.0-r1
1.16.1-r3

Open the chart page →

1,024
k8s-node-image-1-13pnnl-miscscripts0.1.252 of 2See more

k8s-node-image-1-13 pnnl-miscscripts 0.1.25

2 of the 2 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda:20181125-1500-nginx-74eafeb809124
nginx@1.16.1-r1
1.16.1-r3
pnnlmiscscripts/k8s-node-image:1.13.11-nginx-12648032cb498
nginx@1.16.1-r1
1.16.1-r3

Open the chart page →

1,582
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2021-23017.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
nginx@1.14.2-2+deb10u1
1.14.2-2+deb10u4

Open the chart page →

8,694

Container images carrying it

13 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
weblate/weblate:4.2.2-169c160d37a3c
nginx@1.14.2-2+deb10u3
1.14.2-2+deb10u4
2
ajanvier/polr:2.3.091ac61b88c85
nginx@1.18.0-r13
1.18.0-r14
1
galaxy/galaxy-stable:v18.018e577a626dfd
nginx@1.4.6-1ubuntu3.8ppa1
1.4.6-1ubuntu3.9+esm2
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
nginx@1.18.0-r0
1.18.0-r2
1
jlesage/handbrake:v1.24.25fa191e3c7ee
nginx@1.18.0-r1
1.18.0-r2
1
lsstsqre/lsp-landing-page:latest4653f18b5418
nginx@1.16.0-r1
1.16.1-r3
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
nginx@1.10.3-1+deb9u3
1.10.3-1+deb9u6
1
openzipkin/zipkin-ui:2.21.0672cbc94256b
nginx@1.16.1-r1
1.16.1-r3
1
pnnlmiscscripts/anaconda:20181125-1500-nginx-74eafeb809124
nginx@1.16.1-r1
1.16.1-r3
1
pnnlmiscscripts/k8s-node-image:1.13.11-nginx-12648032cb498
nginx@1.16.1-r1
1.16.1-r3
1
wallabag/wallabag:2.4.25e4c26a7fb4a
nginx@1.18.0-r1
1.18.0-r2
1
weblate/weblate:3.11.3-182848df56ecd
nginx@1.14.2-2+deb10u1
1.14.2-2+deb10u4
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nginx@1:1.14.1-9.module+el8.0.0+4108+af250afe
1:1.18.0-3.module+el8.4.0+11152+f736ed63.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.