StackRadar

CVE-2021-28170

Medium

Advisory

Published 6 Oct 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
152
of 17,787 indexed, latest versions
Container images
85
deployed by those charts
Fix available
1 of 2
affected packages

Improper Input Validation in Jakarta Expression Language

Carried by container images the latest versions of 152 of 17,787 indexed charts deploy, on 85 images.

Affected packageAffected versionsFixed inImages
jakarta.elmaven3.0.2, 3.0.3, 3.0.3.jbossorg-2, 3.0.3.jbossorg-43.0.455
javax.elmaven3.0.0, 3.0.1-b08, 3.0.1-b11, 3.0.1-b12no fix listed35
OSV records
GHSA-v6w3-2prq-h95f

Charts affected

152 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-28170.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jakarta.el@3.0.3.jbossorg-2
3.0.4

Open the chart page →

28,699
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-28170.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
javax.el@3.0.0
no fix listed

Open the chart page →

5,807

Container images carrying it

85 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
jakarta.el@3.0.3
3.0.4
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
jakarta.el@3.0.3
3.0.4
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jakarta.el@3.0.3
3.0.4
1
lavandadelpatio/tmdb:0.0.2f36af885e915
jakarta.el@3.0.3
3.0.4
1
library/storm:2.4.0bd5d420506d6
jakarta.el@3.0.2
javax.el@3.0.1-b12
3.0.4
no fix listed
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
jakarta.el@3.0.3
3.0.4
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
javax.el@3.0.0
no fix listed
1
ncsa/datawolf:4.7.0af6649d59150
javax.el@3.0.0
no fix listed
1
opensearchproject/opensearch:2.12.0645d3d9390ad
javax.el@3.0.0
no fix listed
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
javax.el@3.0.0
no fix listed
1
openwhisk/invoker:1.0.0f5831ec85525
javax.el@3.0.1-b11
no fix listed
1
owasp/dependency-track:3.8.0efc65e702ee1
jakarta.el@3.0.2
3.0.4
1
platform9community/api-gateway:latest40a4970de568
jakarta.el@3.0.3
javax.el@3.0.1-b11
3.0.4
no fix listed
1
platform9community/customers-service:latest2089811e5cc6
jakarta.el@3.0.3
javax.el@3.0.1-b11
3.0.4
no fix listed
1
platform9community/vets-service:latestd1165c94dfb3
jakarta.el@3.0.3
javax.el@3.0.1-b11
3.0.4
no fix listed
1
platform9community/visits-service:latest8d11b50368c6
jakarta.el@3.0.3
javax.el@3.0.1-b11
3.0.4
no fix listed
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
javax.el@3.0.0
no fix listed
1
refar/apm-api:v5.7.1241373fa2972
jakarta.el@3.0.3
3.0.4
1
refar/apm-operator-server:v5.7.1e5490f050f9f
jakarta.el@3.0.3
3.0.4
1
remche/shinyproxy:2.6.18bcda8a04d3b
javax.el@3.0.1-b11
no fix listed
1
reportportal/service-jobs:5.7.2dc166c58485a
jakarta.el@3.0.3
3.0.4
1
robotshop/rs-shipping:latest89753ab48919
jakarta.el@3.0.3
3.0.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
javax.el@3.0.0
no fix listed
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
jakarta.el@3.0.3
3.0.4
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
javax.el@3.0.1-b12
no fix listed
1
thelastpickle/cassandra-reaper:1.3.09c53996c457d
javax.el@3.0.0
no fix listed
1
thingsboard/tb-node:3.4.1645f43b688f7
javax.el@3.0.0
no fix listed
1
thingsboard/tb-node:3.6.0f40a542832c4
javax.el@3.0.0
no fix listed
1
trinodb/trino:45038c6f24ab1a4
javax.el@3.0.1-b08
no fix listed
1
trinodb/trino:405ee80ab5eeab2
javax.el@3.0.1-b12
no fix listed
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
javax.el@3.0.1-b08
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jakarta.el@3.0.3
3.0.4
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
jakarta.el@3.0.3
3.0.4
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jakarta.el@3.0.3.jbossorg-2
3.0.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
javax.el@3.0.0
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.