StackRadar

CVE-2021-3647

Medium

Advisory

Published 16 Jul 2021In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 2
affected packages

URIjs Vulnerable to Hostname spoofing via backslashes in URL

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
urijsnpm1.19.1, 1.19.5, 1.19.61.19.76
node-uri-jsdeb4.2.2+dfsg-5, 4.4.0+dfsg-8no fix listed3
OSV records
GHSA-89gv-h8wf-cg8rUBUNTU-CVE-2021-3647

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-uri-js@4.4.0+dfsg-8
no fix listed

Open the chart page →

13,220
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
urijs@1.19.1
1.19.7

Open the chart page →

11,174
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
kubebb/tamp-portal:v5.6.0fadac6d52470
urijs@1.19.6
1.19.7

Open the chart page →

4,664
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
refar/apm-portal:v5.7.1dcca8e4477a6
urijs@1.19.6
1.19.7

Open the chart page →

10,264
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-uri-js@4.2.2+dfsg-5
no fix listed

Open the chart page →

17,779
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
urijs@1.19.6
1.19.7

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
urijs@1.19.6
1.19.7

Open the chart page →

19,226
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
urijs@1.19.6
1.19.7

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
urijs@1.19.6
1.19.7

Open the chart page →

11,554
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-uri-js@4.2.2+dfsg-5
no fix listed

Open the chart page →

10,902
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-3647.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
urijs@1.19.5
1.19.7

Open the chart page →

10,127

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
urijs@1.19.6
1.19.7
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
urijs@1.19.6
1.19.7
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
urijs@1.19.1
1.19.7
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-uri-js@4.4.0+dfsg-8
no fix listed
1
kubebb/tamp-portal:v5.6.0fadac6d52470
urijs@1.19.6
1.19.7
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-uri-js@4.2.2+dfsg-5
no fix listed
1
refar/apm-portal:v5.7.1dcca8e4477a6
urijs@1.19.6
1.19.7
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-uri-js@4.2.2+dfsg-5
no fix listed
1
ubercadence/web:v3.29.58564a5b44a6d
urijs@1.19.5
1.19.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.