StackRadar

CVE-2021-31684

High

Advisory

Published 10 Feb 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
35
of 17,781 indexed, latest versions
Container images
38
deployed by those charts
Fix available
1 of 1
affected package

Out of bounds read in json-smart

Carried by container images the latest versions of 35 of 17,781 indexed charts deploy, on 38 images.

Affected packageAffected versionsFixed inImages
json-smartmaven1.3.1, 1.3.2, 2.4.21.3.3, 2.4.438
OSV records
GHSA-fg2v-w576-w4v3

Charts affected

35 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
json-smart@2.4.2
2.4.4

Open the chart page →

6,556
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
json-smart@1.3.2
1.3.3

Open the chart page →

3,812
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
json-smart@2.4.2
2.4.4

Open the chart page →

2,640
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
json-smart@1.3.2
1.3.3

Open the chart page →

5,357
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
json-smart@1.3.2
1.3.3

Open the chart page →

12,111
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
json-smart@1.3.2
1.3.3

Open the chart page →

7,930
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
json-smart@1.3.2
1.3.3
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
json-smart@1.3.2
1.3.3

Open the chart page →

8,698
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
json-smart@1.3.2
1.3.3

Open the chart page →

7,166
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
json-smart@1.3.1
1.3.3

Open the chart page →

8,198
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
json-smart@1.3.2
1.3.3

Open the chart page →

17,896
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
json-smart@2.4.2
2.4.4

Open the chart page →

38,346
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
json-smart@2.4.2
2.4.4

Open the chart page →

17,284
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
json-smart@1.3.2
1.3.3

Open the chart page →

12,019
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
json-smart@2.4.2
2.4.4

Open the chart page →

31,844
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
json-smart@1.3.2
1.3.3

Open the chart page →

6,045
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
json-smart@1.3.2
1.3.3

Open the chart page →

7,835
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
json-smart@1.3.1
1.3.3
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
json-smart@1.3.1
1.3.3
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
json-smart@1.3.1
1.3.3
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
json-smart@1.3.1
1.3.3
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
json-smart@1.3.1
1.3.3
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
json-smart@1.3.1
1.3.3

Open the chart page →

58,857
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
json-smart@1.3.2
1.3.3

Open the chart page →

10,564
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
json-smart@1.3.2
1.3.3
gchq/hdfs:3.3.35ec58edbb2db
json-smart@1.3.2
1.3.3

Open the chart page →

16,892
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
json-smart@1.3.2
1.3.3

Open the chart page →

9,342
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
json-smart@1.3.2
1.3.3

Open the chart page →

4,556
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
json-smart@1.3.2
1.3.3

Open the chart page →

10,540
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
json-smart@1.3.2
1.3.3

Open the chart page →

8,541
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
ibmcom/app-nav-api:1.0.1ce9d2a564273
json-smart@1.3.1
1.3.3

Open the chart page →

32,915
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
json-smart@1.3.2
1.3.3

Open the chart page →

5,759
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
json-smart@1.3.2
1.3.3

Open the chart page →

5,759
elastictranscoderluiscajl0.46.03 of 4See more

elastictranscoder luiscajl 0.46.0

3 of the 4 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
json-smart@1.3.2
1.3.3
elastictranscoder/media-storage:f6d861a026208b8c2359
json-smart@1.3.2
1.3.3
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
json-smart@1.3.2
1.3.3

Open the chart page →

58,160
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
json-smart@1.3.2
1.3.3

Open the chart page →

2,141
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
json-smart@2.4.2
2.4.4

Open the chart page →

9,300
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
json-smart@2.4.2
2.4.4

Open the chart page →

2,640
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
json-smart@1.3.2
1.3.3

Open the chart page →

8,540
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
json-smart@1.3.2
1.3.3

Open the chart page →

1,995
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
json-smart@1.3.2
1.3.3

Open the chart page →

21,211
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
json-smart@1.3.1
1.3.3

Open the chart page →

13,079
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-31684.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
json-smart@1.3.2
1.3.3

Open the chart page →

4,240

Container images carrying it

38 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gchq/hdfs:3.3.35ec58edbb2db
json-smart@1.3.2
1.3.3
3
apache/druid:37.0.00116fb802786
json-smart@1.3.2
1.3.3
2
inaccel/coral:2.18c53744ed70b
json-smart@1.3.2
1.3.3
2
library/elasticsearch:7.17.35e6ac15bf6a5
json-smart@2.4.2
2.4.4
2
library/neo4j:4.3.2-enterprise56a9453c4064
json-smart@2.4.2
2.4.4
2
5200710/hadoop:3.2.3-java8092d3088a5fb
json-smart@1.3.2
1.3.3
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
json-smart@1.3.2
1.3.3
1
adityaprasadpathak/myapp:3.07e3b9777362c
json-smart@1.3.2
1.3.3
1
apache/druid:29.0.10cef139b6bf1
json-smart@1.3.2
1.3.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
json-smart@1.3.2
1.3.3
1
apache/hadoop:3af361b20bec0
json-smart@1.3.2
1.3.3
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
json-smart@1.3.2
1.3.3
1
atlassian/jira-software:8.14.037bc46cbec1a
json-smart@1.3.1
1.3.3
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
json-smart@1.3.1
1.3.3
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
json-smart@1.3.1
1.3.3
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
json-smart@1.3.1
1.3.3
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
json-smart@1.3.1
1.3.3
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
json-smart@1.3.1
1.3.3
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
json-smart@1.3.1
1.3.3
1
elastictranscoder/media:627e21dc963ab3858c6b
json-smart@1.3.2
1.3.3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
json-smart@1.3.2
1.3.3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
json-smart@1.3.2
1.3.3
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
json-smart@1.3.2
1.3.3
1
gchq/accumulo:2.0.1c460bb587d6d
json-smart@1.3.2
1.3.3
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
json-smart@1.3.1
1.3.3
1
library/elasticsearch:7.17.0332c6d416808
json-smart@2.4.2
2.4.4
1
library/elasticsearch:7.17.8fdc73b3249c1
json-smart@1.3.2
1.3.3
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
json-smart@1.3.2
1.3.3
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
json-smart@1.3.2
1.3.3
1
library/sonarqube:10.0.0-communityef9723cf4fe4
json-smart@2.4.2
2.4.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
json-smart@1.3.1
1.3.3
1
trinodb/trino:45038c6f24ab1a4
json-smart@1.3.2
1.3.3
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
json-smart@2.4.2
2.4.4
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
json-smart@1.3.2
1.3.3
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
json-smart@1.3.2
1.3.3
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
json-smart@1.3.2
1.3.3
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
json-smart@1.3.2
1.3.3
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
json-smart@1.3.2
1.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.