StackRadar

CVE-2021-24112

Critical

Advisory

Published 24 May 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
27
deployed by those charts
Fix available
1 of 1
affected package

.NET Core Remote Code Execution Vulnerability

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 27 images.

Affected packageAffected versionsFixed inImages
System.Drawing.Commonnuget4.6.0, 4.7.0, 5.0.0, 5.0.24.7.2, 5.0.327
OSV records
GHSA-rxg9-xrhp-64gj
Also known as
BIT-dotnet-2021-24112, BIT-dotnet-sdk-2021-24112

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
System.Drawing.Common@5.0.2
5.0.3

Open the chart page →

4,244
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.8.1305a9734d7e83
System.Drawing.Common@5.0.2
5.0.3

Open the chart page →

14,238
eshoponabpabp-charts1.0.08 of 15See more

eshoponabp abp-charts 1.0.0

8 of the 15 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/volosoft/eshoponabp/app-authserver:1.0.022ce496c67d7
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/app-publicweb:1.0.07e53010dda55
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
System.Drawing.Common@5.0.0
5.0.3
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
System.Drawing.Common@5.0.0
5.0.3

Open the chart page →

19,799
voice-biometricslumenvox2.0.14 of 26See more

voice-biometrics lumenvox 2.0.1

4 of the 26 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
System.Drawing.Common@5.0.0
5.0.3
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
System.Drawing.Common@5.0.0
5.0.3
lumenvox/cloud-management-api:2.0.0b9a23345eabd
System.Drawing.Common@5.0.0
5.0.3
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
System.Drawing.Common@5.0.0
5.0.3

Open the chart page →

70,741
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.12 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

2 of the 7 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
System.Drawing.Common@4.7.0
4.7.2
aidasi/swpidentity:v1-1-net6-k8s-test-betad433285c7d5a
System.Drawing.Common@5.0.0
5.0.3

Open the chart page →

10,091
jellyfingeek-cookbookVerified publisher9.5.31 of 1See more

jellyfin geek-cookbook 9.5.3

1 of the 1 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.8.1ee24f4459a40
System.Drawing.Common@5.0.2
5.0.3

Open the chart page →

1,381
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
System.Drawing.Common@4.7.0
4.7.2

Open the chart page →

14,283
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
System.Drawing.Common@5.0.0
5.0.3

Open the chart page →

7,768
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
System.Drawing.Common@4.7.0
4.7.2

Open the chart page →

49,025
smtp4devimioVerified publisher0.1.11 of 1See more

smtp4dev imio 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
rnwood/smtp4dev:3.6.1912304153668
System.Drawing.Common@4.6.0
4.7.2

Open the chart page →

3,192
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
System.Drawing.Common@4.7.0
4.7.2

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
System.Drawing.Common@4.7.0
4.7.2

Open the chart page →

8,361
myweatherhelmmyweather1.3.112 of 7See more

myweatherhelm myweather 1.3.11

2 of the 7 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingservice:1.3.11203ee6853a27
System.Drawing.Common@4.7.0
4.7.2
hecrom/myweatherservice:1.3.11c502a4b758f0
System.Drawing.Common@4.7.0
4.7.2

Open the chart page →

17,929
dotstatsuitestatcan0.2.81 of 6See more

dotstatsuite statcan 0.2.8

1 of the 6 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
siscc/dotstatsuite-core-sdmxri-nsi:master00d73f06edcf
System.Drawing.Common@4.7.0
4.7.2

Open the chart page →

3,841
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2021-24112.

Container imageDigestPackageFixed in
thecloudspark/app-worker:1.0dbfcfe02bf36
System.Drawing.Common@5.0.0
5.0.3

Open the chart page →

3,031

Container images carrying it

27 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aidasi/swpapi:v1-1-net6-k8s-test-beta838b5e2080bc
System.Drawing.Common@4.7.0
4.7.2
1
aidasi/swpidentity:v1-1-net6-k8s-test-betad433285c7d5a
System.Drawing.Common@5.0.0
5.0.3
1
hecrom/myweatherprocessingservice:1.3.11203ee6853a27
System.Drawing.Common@4.7.0
4.7.2
1
hecrom/myweatherservice:1.3.11c502a4b758f0
System.Drawing.Common@4.7.0
4.7.2
1
jellyfin/jellyfin:10.8.1305a9734d7e83
System.Drawing.Common@5.0.2
5.0.3
1
jellyfin/jellyfin:10.8.1ee24f4459a40
System.Drawing.Common@5.0.2
5.0.3
1
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
System.Drawing.Common@5.0.0
5.0.3
1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
System.Drawing.Common@5.0.0
5.0.3
1
lumenvox/cloud-management-api:2.0.0b9a23345eabd
System.Drawing.Common@5.0.0
5.0.3
1
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
System.Drawing.Common@5.0.0
5.0.3
1
rnwood/smtp4dev:3.6.1912304153668
System.Drawing.Common@4.6.0
4.7.2
1
siscc/dotstatsuite-core-sdmxri-nsi:master00d73f06edcf
System.Drawing.Common@4.7.0
4.7.2
1
thecloudspark/app-worker:1.0dbfcfe02bf36
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
System.Drawing.Common@5.0.2
5.0.3
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
System.Drawing.Common@4.7.0
4.7.2
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
System.Drawing.Common@4.7.0
4.7.2
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
System.Drawing.Common@4.7.0
4.7.2
1
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
System.Drawing.Common@4.7.0
4.7.2
1
ghcr.io/volosoft/eshoponabp/app-authserver:1.0.022ce496c67d7
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/app-publicweb:1.0.07e53010dda55
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
System.Drawing.Common@5.0.0
5.0.3
1
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
System.Drawing.Common@5.0.0
5.0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.