CVE-2021-23017
HighAdvisory
Published 25 May 2021In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.1
- base score, highest
- EPSS
- 0.535
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 13
- of 17,781 indexed, latest versions
- Container images
- 13
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: nginx:1.18 security update
Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 13 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nginxrpm | 1:1.14.1-9.module+el8.0.0+4108+af250afe | 1:1.18.0-3.module+el8.4.0+11152+f736ed63.1 | 1 |
| nginxapk | 1.16.0-r1, 1.16.1-r1, 1.18.0-r0, 1.18.0-r1+1 more | 1.16.1-r3, 1.18.0-r2, 1.18.0-r14 | 8 |
| nginxdeb | 1.4.6-1ubuntu3.8ppa1, 1.10.3-1+deb9u3, 1.14.2-2+deb10u1, 1.14.2-2+deb10u3 | 1.4.6-1ubuntu3.9+esm2, 1.10.3-1+deb9u6, 1.14.2-2+deb10u4 | 4 |
- OSV records
- ALPINE-CVE-2021-23017RHSA-2021:2259UBUNTU-CVE-2021-23017DLA-2670-1DSA-4921-1
- Also known as
- RHSA-2021:2290, RHSA-2022:0323, USN-4967-2
Charts affected
13 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zipkincarlosjgp | 0.2.0 | 1 of 2See more | 3,229 |
| netris-controllernetrisai | 2.8.2 | 1 of 14See more | 30,326 |
| weblatedeliveryheroVerified publisher | 0.3.2 | 1 of 3See more | 7,984 |
| helm-taigamvitale1989-helm-taigaVerified publisher | 0.2.5 | 1 of 2See more | 5,104 |
| polrchristianhuthVerified publisher | 4.3.0 | 1 of 2See more | 5,904 |
| cp4d-deployercloud-native-toolkit | 1.0.0 | 1 of 1See more | 25,151 |
| galaxy-stablecloudve | 2.0.0 | 1 of 5See more | 70,895 |
| handbrakegeek-cookbookVerified publisher | 0.1.2 | 1 of 1See more | 1,469 |
| wallabaggeek-cookbookVerified publisher | 7.2.0 | 1 of 1See more | 4,358 |
| weblatehelm-charts-nr | 0.3.2 | 1 of 3See more | 7,984 |
| landing-pagelsst-sqre | 0.3.0 | 1 of 1See more | 1,024 |
| k8s-node-image-1-13pnnl-miscscripts | 0.1.25 | 2 of 2See more | 1,582 |
| weblateslamdev | 0.0.11 | 1 of 2See more | 8,694 |
Container images carrying it
13 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| weblate/ | 69c160d37a3c | nginx | 1.14.2-2+deb10u4 | 2 |
| ajanvier/ | 91ac61b88c85 | nginx | 1.18.0-r14 | 1 |
| galaxy/ | 8e577a626dfd | nginx | 1.4.6-1ubuntu3.9+esm2 | 1 |
| graphiteapp/ | 04a0037cc2ae | nginx | 1.18.0-r2 | 1 |
| jlesage/ | 5fa191e3c7ee | nginx | 1.18.0-r2 | 1 |
| lsstsqre/ | 4653f18b5418 | nginx | 1.16.1-r3 | 1 |
| mvitale1989/ | 1504ccda06df | nginx | 1.10.3-1+deb9u6 | 1 |
| openzipkin/ | 672cbc94256b | nginx | 1.16.1-r3 | 1 |
| pnnlmiscscripts/ | 4eafeb809124 | nginx | 1.16.1-r3 | 1 |
| pnnlmiscscripts/ | 2648032cb498 | nginx | 1.16.1-r3 | 1 |
| wallabag/ | 5e4c26a7fb4a | nginx | 1.18.0-r2 | 1 |
| weblate/ | 82848df56ecd | nginx | 1.14.2-2+deb10u4 | 1 |
| quay.io/ | 13aaae779248 | nginx | 1:1.18.0-3.module+el8.4.0+11152+f736ed63.1 | 1 |