StackRadar

CVE-2021-3572

Medium

Advisory

Published 10 Nov 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.7
base score, highest
EPSS
0.018
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
377
deployed by those charts
Fix available
3 of 3
affected packages

Improper Input Validation in pip

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 377 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+27 more21.1365
python-pipdeb1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+3 more1.5.4-1ubuntu4+esm1, 8.1.1-2ubuntu0.6+esm2, 9.0.1-2.3~ubuntu1.18.04.5+esm227
python-piprpm9.0.3-15.el8, 9.0.3-16.el8, 9.0.3-18.el8, 9.0.3-19.el80:9.0.3-20.el835
OSV records
GHSA-5xp3-jfq3-5q8xRHSA-2021:4455UBUNTU-CVE-2021-3572
Also known as
PYSEC-2021-437, USN-4961-2

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
pip@21.0.1
21.1

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
pip@20.2.3
21.1

Open the chart page →

3,044
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
pip@20.1
21.1

Open the chart page →

12,237
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
pip@20.0.2
21.1

Open the chart page →

10,134
csv-viewsvtech-public-helm-charts1.0.01 of 1See more

csv-view svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
pip@20.2.2
21.1

Open the chart page →

1,220
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
21.1

Open the chart page →

12,655
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
pip@9.0.3
21.1

Open the chart page →

5,511
icinga2-reportsvtech-public-helm-charts1.0.01 of 1See more

icinga2-report svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
pip@20.1.1
21.1

Open the chart page →

1,779
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
pip@20.2.4
21.1

Open the chart page →

5,841
rundeck-option-providersvtech-public-helm-charts1.0.01 of 2See more

rundeck-option-provider svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
pip@20.2.2
21.1

Open the chart page →

1,428
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
pip@20.1
21.1

Open the chart page →

1,287
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
pip@8.1.2
21.1

Open the chart page →

4,240
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
pip@20.2.2
21.1

Open the chart page →

4,423
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
python-pip@9.0.3-19.el8
0:9.0.3-20.el8

Open the chart page →

12,455
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
pip@9.0.3
21.1

Open the chart page →

1,733
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
pip@20.0.2
21.1

Open the chart page →

2,670
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
pip@9.0.3
python-pip@9.0.3-19.el8
21.1
0:9.0.3-20.el8

Open the chart page →

28,605
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
pip@20.2.4
21.1

Open the chart page →

4,086
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
pip@19.2.3
21.1

Open the chart page →

4,984
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
pip@9.0.3
21.1

Open the chart page →

6,138
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
pip@20.3.4
21.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pip@9.0.3
21.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pip@9.0.3
21.1

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
pip@21.0
21.1

Open the chart page →

1,843
pypiwiremindVerified publisher0.2.11 of 1See more

pypi wiremind 0.2.1

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
codekoala/pypi:1.2.14a999b2cfff2
pip@9.0.1
21.1

Open the chart page →

423
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2021-3572.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
pip@9.0.3
21.1

Open the chart page →

6,016

Container images carrying it

377 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
statcan/ckan:2.93921305425b8
pip@20.0.2
21.1
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
pip@20.0.2
21.1
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
pip@18.1
21.1
1
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
pip@20.2.2
21.1
1
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
pip@9.0.3
21.1
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
pip@20.2.2
21.1
1
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
pip@20.1
21.1
1
taigaio/taiga-protected:6.4.036318831b3e7
pip@21.0.1
21.1
1
temporalio/admin-tools:1.15.135034611d981
pip@20.3.4
21.1
1
tenableofficial/nessus:latestc88e43fe1a8c
pip@9.0.3
21.1
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
pip@9.0.1
21.1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
21.1
8.1.1-2ubuntu0.6+esm2
1
tobiasbp/db-backup:0.0.314bee6e33a26
pip@20.1.1
21.1
1
trungkien210493/icinga2-report:v1.7.12cc8c3763c4c
pip@20.1.1
21.1
1
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
pip@21.0
21.1
1
voltha/voltha-cli:1.6.0c4e41e92f046
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
21.1
8.1.1-2ubuntu0.6+esm2
1
voltha/voltha-netconf:1.6.037f80524c207
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
21.1
8.1.1-2ubuntu0.6+esm2
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
21.1
8.1.1-2ubuntu0.6+esm2
1
voltha/voltha-tester:1.7.0655c3048a602
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
21.1
8.1.1-2ubuntu0.6+esm2
1
voltha/voltha-voltha:1.6.0ff596b62de59
pip@8.1.1
python-pip@8.1.1-2ubuntu0.4
21.1
8.1.1-2ubuntu0.6+esm2
1
weblate/weblate:3.11.3-182848df56ecd
pip@18.1
21.1
1
wiremind/pghoard:12-2019-11-264dea42c8166c
pip@19.3.1
21.1
1
ygqygq2/mysql-exec-sql:latest54f30def1558
pip@20.2.4
21.1
1
yugabytedb/yugabyte:2026.1.1.1-b23926eedf0ff4
pip@9.0.3
21.1
1
yugabytedb/yugabyte:2026.1.1.0-b91de2e00278645
pip@9.0.3
21.1
1
zohardocker12/weather_app_flask:latestb86d60dbb68d
pip@20.0.2
21.1
1
gcr.io/google-samples/microservices-demo/loadgenerator:v0.2.3360130ab5850
pip@21.0.1
21.1
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
pip@21.0.1
21.1
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
pip@9.0.3
21.1
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
pip@20.3.4
21.1
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
pip@20.3.4
21.1
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
pip@20.3.4
21.1
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pip@20.3.4
21.1
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pip@20.3.4
21.1
1
ghcr.io/cloudnative-pg/postgresql:18899d3ed526b6
pip@20.3.4
21.1
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
pip@20.3.4
21.1
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
python-pip@9.0.3-19.el8
0:9.0.3-20.el8
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
python-pip@9.0.3-19.el8
0:9.0.3-20.el8
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
python-pip@9.0.3-19.el8
0:9.0.3-20.el8
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
python-pip@9.0.3-19.el8
0:9.0.3-20.el8
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
python-pip@9.0.3-19.el8
0:9.0.3-20.el8
1
ghcr.io/dynamia-ai/hami-enterprise:v2.10.0-r0-openshift.c4e22e88745504757300
pip@9.0.3
21.1
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
pip@20.2.4
21.1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
python-pip@9.0.3-16.el8
0:9.0.3-20.el8
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
pip@20.0.2
21.1
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
pip@20.0.2
21.1
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pip@20.3.4
21.1
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
pip@20.3.4
21.1
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
pip@20.3.4
21.1
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
pip@20.0.2
21.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.