StackRadar

CVE-2021-3572

Medium

Advisory

Published 10 Nov 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.7
base score, highest
EPSS
0.018
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
377
deployed by those charts
Fix available
3 of 3
affected packages

Improper Input Validation in pip

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 377 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+27 more21.1365
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+3 more1.5.4-1ubuntu4+esm1, 8.1.1-2ubuntu0.6+esm2, 9.0.1-2.3~ubuntu1.18.04.5+esm227
python-piprpm9.0.3-15.el8, 9.0.3-16.el8, 9.0.3-18.el8, 9.0.3-19.el80:9.0.3-20.el835
OSV records
GHSA-5xp3-jfq3-5q8xRHSA-2021:4455UBUNTU-CVE-2021-3572
Also known as
PYSEC-2021-437, USN-4961-2

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
argocd-ecr-updaterargocd-ecr-updater4.1.01 of 1See more

argocd-ecr-updater argocd-ecr-updater 4.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
odaniait/aws-kubectl:latest3fff8a8570ec
pip@20.0.2
21.1

Open the chart page →

1,511
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
21.1

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
21.1

Open the chart page →

2,418
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
pip@20.2.4
21.1

Open the chart page →

5,537
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
pip@20.2.4
21.1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
pip@20.2.4
21.1

Open the chart page →

14,728
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
assistiot/fl_repository:latest0fce3ea719a5
pip@20.1.1
21.1

Open the chart page →

4,367
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
pip@9.0.3
21.1

Open the chart page →

13,352
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pip@20.3.4
21.1

Open the chart page →

10,061
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
pip@20.3.4
21.1

Open the chart page →

8,032
aws-ecr-credentialaws-ecr-credentialVerified publisher1.5.21 of 1See more

aws-ecr-credential aws-ecr-credential 1.5.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
architectminds/aws-kubectl:1.19735e59a1085
pip@19.2.1
21.1

Open the chart page →

1,437
ecr-exporteraws-exportersVerified publisher0.2.41 of 1See more

ecr-exporter aws-exporters 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
pip@20.3.4
21.1

Open the chart page →

1,622
inspector-exporteraws-exportersVerified publisher0.0.21 of 1See more

inspector-exporter aws-exporters 0.0.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
pip@20.3.4
21.1

Open the chart page →

1,622
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
pip@20.2.4
21.1

Open the chart page →

5,521
aks-helloworldazure-sample0.1.11 of 1See more

aks-helloworld azure-sample 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/aks-helloworld:v1fb47732ef36b
pip@9.0.1
21.1

Open the chart page →

4,269
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
21.1

Open the chart page →

5,224
azure-vote-osbaazure-sample0.1.01 of 1See more

azure-vote-osba azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
pip@9.0.1
21.1

Open the chart page →

4,269
osba-container-instances-demoazure-sample0.1.01 of 1See more

osba-container-instances-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
pip@9.0.1
21.1

Open the chart page →

3,212
osba-cosmos-mongodb-demoazure-sample0.1.01 of 1See more

osba-cosmos-mongodb-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
pip@9.0.1
21.1

Open the chart page →

2,904
osba-mysql-demoazure-sample0.1.01 of 1See more

osba-mysql-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
pip@9.0.2
21.1

Open the chart page →

2,895
osba-storage-demoazure-sample0.1.01 of 1See more

osba-storage-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/osba-storage-demo:latest29d229ab446e
pip@9.0.1
21.1

Open the chart page →

3,425
osba-text-analytics-demoazure-sample0.1.01 of 1See more

osba-text-analytics-demo azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
pip@10.0.1
21.1

Open the chart page →

3,089
twitter-sentimentazure-sample0.1.03 of 3See more

twitter-sentiment azure-sample 0.1.0

3 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
neilpeterson/chart-tweet:latest64fd8dab075f
pip@9.0.1
21.1
neilpeterson/get-tweet:v28b645ac1a23e
pip@10.0.1
21.1
neilpeterson/process-tweet:latest39ce9f92e899
pip@10.0.1
21.1

Open the chart page →

11,833
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
conduction/balance-registration-varnish:dev07c44005da9d
pip@9.0.1
21.1

Open the chart page →

8,408
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
pip@20.1.1
21.1

Open the chart page →

20,671
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
pip@20.0.2
21.1

Open the chart page →

7,956
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
pip@9.0.1
python-pip@9.0.1-2.3~ubuntu1.18.04.5
21.1
9.0.1-2.3~ubuntu1.18.04.5+esm2

Open the chart page →

22,891
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
istio/examples-bookinfo-productpage-v1:1.15.00a5eb4795952
pip@19.1.1
21.1

Open the chart page →

18,980
puppetboardbootcVerified publisher0.1.41 of 1See more

puppetboard bootc 0.1.4

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
bootc/puppetboard:1.1.0f1383295e7be
pip@19.2.3
21.1

Open the chart page →

1,292
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
21.1

Open the chart page →

2,018
medusabryanalves0.1.01 of 1See more

medusa bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
21.1

Open the chart page →

147
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
21.1

Open the chart page →

2,504
sickragebryanalves0.1.01 of 1See more

sickrage bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
bryanalves/sickrage:latest42f0a130001d
pip@9.0.0
21.1

Open the chart page →

923
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pip@20.3.4
21.1

Open the chart page →

2,573
ekorrecamptocamp30.1.11 of 1See more

ekorre camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
camptocamp/ekorre:0.1.035c91d5fda04
pip@20.0.2
21.1

Open the chart page →

3,891
pghoardcamptocamp35.8.11 of 1See more

pghoard camptocamp3 5.8.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
camptocamp/pghoard:10bff736b15623
pip@18.1
21.1

Open the chart page →

2,813
prometheus-operatorcamptocamp35.15.11 of 5See more

prometheus-operator camptocamp3 5.15.1

1 of the 5 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
pip@19.0.3
21.1

Open the chart page →

2,490
snow-webhookcamptocamp31.0.01 of 1See more

snow-webhook camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
camptocamp/snow-webhook:latest2924b43dbf40
pip@18.1
21.1

Open the chart page →

1,310
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
pip@8.1.2
21.1

Open the chart page →

12,018
pypi-servercgsimmons0.1.01 of 1See more

pypi-server cgsimmons 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v1.3.2303ac89b2aa2
pip@19.3.1
21.1

Open the chart page →

506
ctk-walkthroughchaostoolkit-walkthrough0.1.03 of 3See more

ctk-walkthrough chaostoolkit-walkthrough 0.1.0

3 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
chaostoolkit/back:latest734f3af86125
pip@20.2.4
21.1
chaostoolkit/front:latest7f4a7eb9f7df
pip@20.2.4
21.1
chaostoolkit/middle:latestb95ba4961cfc
pip@20.3
21.1

Open the chart page →

5,557
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
conduction/checkin-component-varnish:devef3a3fb0ad47
pip@9.0.1
21.1

Open the chart page →

8,408
syncserverchristianhuthVerified publisher1.3.01 of 1See more

syncserver christianhuth 1.3.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
mozilla/syncserver:latest016162bf39d8
pip@20.3.4
21.1

Open the chart page →

1,382
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pip@10.0.1
21.1

Open the chart page →

2,408
couchdbcloudnativeapp1.1.31 of 3See more

couchdb cloudnativeapp 1.1.3

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kocolosk/couchdb-statefulset-assembler:1.2.06effb982154e
pip@9.0.1
21.1

Open the chart page →

2,110
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pip@10.0.1
21.1
daskdev/dask-notebook:1.1.0052630f5ca04
pip@18.1
21.1

Open the chart page →

29,901
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
pip@9.0.1
21.1

Open the chart page →

36,094
k8s-spot-termination-handlercloudnativeapp1.2.11 of 1See more

k8s-spot-termination-handler cloudnativeapp 1.2.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
pip@19.0.3
21.1

Open the chart page →

2,095
kube-huntercloudnativeapp1.0.21 of 1See more

kube-hunter cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
aquasec/kube-hunter:1950bf607ce9308
pip@18.1
21.1

Open the chart page →

1,305
locustcloudnativeapp1.0.01 of 1See more

locust cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
greenbirdit/locust:0.9.0e99d53bdc944
pip@18.1
21.1

Open the chart page →

1,352
prometheus-operatorcloudnativeapp6.4.01 of 7See more

prometheus-operator cloudnativeapp 6.4.0

1 of the 7 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
pip@19.1.1
21.1

Open the chart page →

2,954

Container images carrying it

377 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
coderenvs/timescale:1.44.676fd37fe6830
pip@9.0.3
21.1
1
conduction/balance-registration-varnish:dev07c44005da9d
pip@9.0.1
21.1
1
conduction/cgrc-varnish:deve154d5781c8a
pip@9.0.1
21.1
1
conduction/checkin-component-varnish:devef3a3fb0ad47
pip@9.0.1
21.1
1
conduction/conduction-ui-varnish:dev5f5add2c12e0
pip@9.0.1
21.1
1
conduction/contactmoment-component-varnish:deve3546b97faea
pip@9.0.1
21.1
1
conduction/docparser-varnish:dev45f20c4cd2fa
pip@9.0.1
21.1
1
conduction/kvk-varnish:dev8722700f1768
pip@9.0.1
21.1
1
conduction/pan-varnish:devc3e5737ae68f
pip@9.0.1
21.1
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
confluentinc/cp-kafka:5.4.01bbda887bc53
pip@8.1.2
21.1
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
pip@9.0.3
21.1
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
pip@20.2.4
21.1
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
pip@9.0.3
21.1
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
pip@9.0.3
21.1
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
pip@8.1.2
21.1
1
confluentinc/cp-kafka:7.5.1dc9b972db002
pip@20.2.4
21.1
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
pip@20.2.4
21.1
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
pip@20.2.4
21.1
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
pip@20.2.4
21.1
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
pip@9.0.3
python-pip@9.0.3-18.el8
21.1
0:9.0.3-20.el8
1
craigwillis/c2metadata-bd:latestae317d7e4724
pip@20.1.1
21.1
1
ctron/hawkbit-operator:0.1.48fdea8f76499
python-pip@9.0.3-16.el8
0:9.0.3-20.el8
1
daskdev/dask:1.1.04ecd7bc35500
pip@10.0.1
21.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
pip@18.1
21.1
1
datadog/agent:7.22.08f20e56b5311
pip@20.1.1
21.1
1
datadog/agent:6aad9994de6a7
pip@20.3.3
21.1
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
pip@20.2.4
21.1
1
datawire/aes:1.13.62beb65062c8b
pip@20.2.4
21.1
1
datawire/emissary:2.0.2-ea9716efbdd24b
pip@20.2.4
21.1
1
dbanda/livy:0.80ca125e68e53
pip@20.1.1
21.1
1
dbanda/spark:2.4.6d0e6367876ae
pip@20.1.1
21.1
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
pip@9.0.3
21.1
1
dnationcloud/kubernetes-linter:0.2.1dee6376560f5
pip@18.1
21.1
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
pip@20.0.2
21.1
1
dpage/pgadmin4:4.5a5a656e1d5fd
pip@19.0.3
21.1
1
dpage/pgadmin4:4.22b1f00b8163cf
pip@20.1.1
21.1
1
drgrove/mtls-server:v0.14.2361721759a2b
pip@19.1.1
21.1
1
dysnix/pritunl:v1.29-r819951e3e7a32
pip@20.2.2
21.1
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
pip@18.1
21.1
1
esphome/esphome:1.18.03f51ec10e823
pip@18.1
21.1
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
pip@10.0.1
21.1
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
pip@20.0.2
21.1
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
pip@21.0.1
21.1
1
flyway/flyway:9.1545b5d7cdc75a
pip@20.0.2
21.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.