CVE-2021-23438
MediumAdvisory
Published 2 Sept 2021In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.6
- base score, highest
- EPSS
- 0.017
- 76th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 9
- of 17,781 indexed, latest versions
- Container images
- 9
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Type confusion in mpath
Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| mpathnpm | 0.3.0, 0.5.2, 0.6.0, 0.8.3 | 0.8.4 | 9 |
- OSV records
- GHSA-p92x-r36w-9395
Charts affected
9 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| open5gsadaptivenetlabVerified publisher | 1.0.3 | 1 of 3See more | 25,443 |
| backend-charteks-3-tier-app-chart | 0.1.0 | 1 of 1See more | 1,693 |
| iotagent-ulfiware | 0.1.2 | 1 of 1See more | 3,337 |
| Governify-Bluejaygovernify | 0.1.0 | 2 of 12See more | 22,512 |
| Governify-Falcongovernify | 0.1.0 | 3 of 10See more | 24,319 |
| yapijoelee2012Verified publisher | 0.2.0 | 1 of 1See more | 6,454 |
| admin-api-svcmojaloop | 12.0.0 | 1 of 4See more | 12,108 |
| mojaloopmojaloop | 14.0.0 | 1 of 6See more | 19,226 |
| pock-helm-charttinote-chart | 0.1.0 | 1 of 3See more | 6,881 |
Container images carrying it
9 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| governify/ | 608c6940bb98 | mpath | 0.8.4 | 2 |
| governify/ | d3f37f4f8168 | mpath | 0.8.4 | 2 |
| mojaloop/ | 1abc8a7aa71c | mpath | 0.8.4 | 2 |
| arfath29/ | ee0750b18406 | mpath | 0.8.4 | 1 |
| denisshav/ | 4cc8dc5a4499 | mpath | 0.8.4 | 1 |
| fiware/ | fe11f55a926d | mpath | 0.8.4 | 1 |
| governify/ | 6d3d1a5b46a9 | mpath | 0.8.4 | 1 |
| jayfong/ | 163e5d621910 | mpath | 0.8.4 | 1 |
| registry.gitlab.com/ | fda21b0a0344 | mpath | 0.8.4 | 1 |