StackRadar

CVE-2021-33203

Medium

Advisory

Published 8 Jun 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.9
base score, highest
EPSS
0.027
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

Path Traversal in Django

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
djangopypi1.11.11, 1.11.24, 1.11.29, 2.2.13+5 more2.2.24, 3.1.12, 3.2.411
OSV records
GHSA-68w8-qjq3-2gfm
Also known as
BIT-django-2021-33203, PYSEC-2021-98

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
django@2.2.13
2.2.24

Open the chart page →

30,326
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
django@1.11.29
2.2.24

Open the chart page →

7,255
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
flagsmith/flagsmith-api:v2.6.0fd58556339a4
django@2.2.17
2.2.24

Open the chart page →

6,868
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
django@3.1.1
3.1.12

Open the chart page →

7,984
healthchecksgeek-cookbookVerified publisher4.4.21 of 1See more

healthchecks geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
linuxserver/healthchecks:version-v1.20.050792a72fc71
django@3.2
3.2.4

Open the chart page →

1,667
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
django@1.11.24
2.2.24

Open the chart page →

5,104
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
django@2.2.14
2.2.24

Open the chart page →

24,293
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
django@3.1.1
3.1.12

Open the chart page →

7,984
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
django@1.11.29
2.2.24

Open the chart page →

6,501
comacopencord1.0.02 of 9See more

comac opencord 1.0.0

2 of the 9 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
2.2.24
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
django@1.11.11
2.2.24

Open the chart page →

88,546
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
2.2.24

Open the chart page →

26,211
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2021-33203.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
3.1.12

Open the chart page →

8,694

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
2.2.24
2
weblate/weblate:4.2.2-169c160d37a3c
django@3.1.1
3.1.12
2
flagsmith/flagsmith-api:v2.6.0fd58556339a4
django@2.2.17
2.2.24
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
django@2.2.13
2.2.24
1
improwised/erpnext-worker:v13.4.197280b55cbd4
django@1.11.29
2.2.24
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
django@3.2
3.2.4
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
django@1.11.24
2.2.24
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
django@1.11.11
2.2.24
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
django@2.2.14
2.2.24
1
taigaio/taiga-back:6.4.29f97323cc150
django@1.11.29
2.2.24
1
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
3.1.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.