CVE-2021-3712
HighAdvisory
Published 24 Aug 2021In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.4
- base score, highest
- EPSS
- 0.504
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,166
- of 17,787 indexed, latest versions
- Container images
- 1,128
- deployed by those charts
- Fix available
- 5 of 5
- affected packages
Red Hat Security Advisory: openssl security update
Carried by container images the latest versions of 1,166 of 17,787 indexed charts deploy, on 1,128 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+59 more | 1.0.1f-1ubuntu2.27+esm4, 1.0.2g-1ubuntu4.20+esm1, 1.1.0l-1~deb9u4, 1.1.1-1ubuntu2.1~18.04.13+2 more | 614 |
| opensslapk | 1.1.1d-r3, 1.1.1g-r0, 1.1.1i-r0, 1.1.1j-r0+1 more | 1.1.1l-r0 | 430 |
| openssl1.0deb | 1.0.2l-2, 1.0.2l-2+deb9u1, 1.0.2l-2+deb9u2, 1.0.2l-2+deb9u3+11 more | 1.0.2n-1ubuntu5.7, 1.0.2u-1~deb9u6 | 108 |
| opensslrpm | 1:1.0.2k-16.el7_6.1, 1:1.0.2k-19.el7, 1:1.0.2k-21.el7_9, 1:1.0.2k-22.el7_9+10 more | 1:1.0.2k-23.el7_9, 1:1.1.1k-5.el8_5 | 76 |
| openssl-1_1rpm | 1.1.0i-14.6.1, 1.1.1d-11.6.1 | 1.1.0i-14.18.1, 1.1.1d-11.30.1 | 8 |
- OSV records
- ALPINE-CVE-2021-3712RHSA-2021:5226RHSA-2022:0064UBUNTU-CVE-2021-3712DLA-2766-1DLA-2774-1SUSE-SU-2021:2831-1SUSE-SU-2021:2966-1
- Also known as
- SUSE-SU-2021:2968-1, USN-5051-1, USN-5051-2, USN-5051-3
Charts affected
1,166 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| nats-account-serverwenerme | 0.8.1 | 1 of 1See more | 2,634 |
| sambawenerme | 1.0.0 | 1 of 1See more | 2,555 |
| temporalwenerme | 0.15.1 | 2 of 13See more | 22,665 |
| traefikwenerme | 9.1.1 | 1 of 1See more | 3,369 |
| docker-hub-rate-limit-exporterwiremindVerified publisher | 0.3.0 | 1 of 1See more | 1,843 |
| kibanawiremindVerified publisher | 8.5.23 | 1 of 2See more | 6,323 |
| nginxwiremindVerified publisher | 2.1.1 | 1 of 1See more | 966 |
| apicurio-registry-sqlwitcom-gmbh | 0.1.0 | 1 of 1See more | 3,424 |
| upsourcexykongVerified publisher | 0.1.1 | 1 of 1See more | 702 |
| helmexampleycztest | 0.1.0 | 1 of 1See more | 702 |
| mychartyi-test-chart | 0.1.0 | 1 of 1See more | 702 |
| rcloneymrs | 0.1.4 | 1 of 2See more | 1,198 |
| version-checkerymrs | 0.2.3 | 1 of 1See more | 3,023 |
| helmexampleyunpeng-helmexample | 0.1.0 | 1 of 1See more | 702 |
| zahori-schedulerzahoriVerified publisher | 1.0.1 | 1 of 1See more | 2,464 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,250 |
Container images carrying it
1,128 by charts deploying them
A fixed version is listed for 5 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | ef035ac10498 | openssl | 1.1.0l-1~deb9u4 | 3 |
| quay.io/ | 7bcf286807b8 | openssl | 1.1.1l-r0 | 3 |
| quay.io/ | c68135620167 | openssl | 1:1.1.1k-5.el8_5 | 3 |
| abutaha/ | 190ed2d1dfc8 | openssl | 1.1.1l-r0 | 2 |
| apteno/ | 74035b864eed | openssl | 1.1.1l-r0 | 2 |
| clickhouse/ | ed9640bfff07 | openssl | no fix listed | 2 |
| crate/ | b8d89fa5d19b | openssl | 1.1.1l-r0 | 2 |
| curlimages/ | 5329ee280d3d | openssl | 1.1.1l-r0 | 2 |
| curlimages/ | fa32ef426092 | openssl | 1.1.1l-r0 | 2 |
| eqalpha/ | 6537505c4235 | openssl | no fix listed | 2 |
| eqalpha/ | eceb1806730c | openssl | no fix listed | 2 |
| fjvela/ | a8ebe5ca13fc | openssl openssl1.0 | 1.1.0l-1~deb9u4 1.0.2u-1~deb9u6 | 2 |
| fjvela/ | 85727d4079d6 | openssl | 1.1.1l-r0 | 2 |
| fjvela/ | 3c840aebce22 | openssl openssl1.0 | 1.1.0l-1~deb9u4 1.0.2u-1~deb9u6 | 2 |
| freeradius/ | 21c8bfa904d8 | openssl | 1.1.1-1ubuntu2.1~18.04.13 | 2 |
| geoservercloud/ | 756559ee788a | openssl | no fix listed | 2 |
| geoservercloud/ | 99540eef78ad | openssl | no fix listed | 2 |
| geoservercloud/ | 5c254c53a357 | openssl | no fix listed | 2 |
| geoservercloud/ | c687b1cbc891 | openssl | no fix listed | 2 |
| geoservercloud/ | 5288f320cf36 | openssl | no fix listed | 2 |
| geoservercloud/ | a30a60ac6cd0 | openssl | no fix listed | 2 |
| giantswarm/ | 58a9d175cdb7 | openssl | 1.1.1l-r0 | 2 |
| governify/ | 2987672448c7 | openssl | 1.1.1l-r0 | 2 |
| governify/ | 608c6940bb98 | openssl | 1.1.1l-r0 | 2 |
| governify/ | d3f37f4f8168 | openssl | 1.1.1l-r0 | 2 |
| governify/ | daeca1ce28e6 | openssl | 1.1.1l-r0 | 2 |
| governify/ | 38595913458f | openssl | 1.1.1l-r0 | 2 |
| grafana/ | 511bc20bfcd1 | openssl | 1.1.1l-r0 | 2 |
| grafana/ | d66b41cf7e05 | openssl openssl1.0 | 1.1.0l-1~deb9u4 1.0.2u-1~deb9u6 | 2 |
| grafana/ | 46e88d390cd6 | openssl | 1.1.0l-1~deb9u4 | 2 |
| hookiesolutions/ | 0629694246ba | openssl | no fix listed | 2 |
| hyperledger/ | a674d35eec9a | openssl | no fix listed | 2 |
| interlayhq/ | a66d0e35e70f | openssl | no fix listed | 2 |
| interlayhq/ | c3e311de67da | openssl | no fix listed | 2 |
| istio/ | 4c3379923c8a | openssl | 1.1.0l-1~deb9u4 | 2 |
| istio/ | fce0bcbff0be | openssl | 1.1.0l-1~deb9u4 | 2 |
| istio/ | 0a5eb4795952 | openssl | 1.1.0l-1~deb9u4 | 2 |
| istio/ | 22a0410f35a8 | openssl | 1.1.0l-1~deb9u4 | 2 |
| istio/ | 09b9d6958a13 | openssl openssl1.0 | 1.1.0l-1~deb9u4 1.0.2u-1~deb9u6 | 2 |
| istio/ | eb0f1a725ca8 | openssl openssl1.0 | 1.1.0l-1~deb9u4 1.0.2u-1~deb9u6 | 2 |
| istio/ | 40e8aba77c1b | openssl | 1.0.2g-1ubuntu4.20+esm1 | 2 |
| istio/ | ee156b8aefd6 | openssl | 1.0.2g-1ubuntu4.20+esm1 | 2 |
| istio/ | e86d247b7ac2 | openssl | 1.0.2g-1ubuntu4.20+esm1 | 2 |
| istio/ | eab80bcd2132 | openssl | 1.0.2g-1ubuntu4.20+esm1 | 2 |
| istio/ | 1e37fca43550 | openssl | 1.0.2g-1ubuntu4.20+esm1 | 2 |
| istio/ | e454cab754cf | openssl | 1.0.2g-1ubuntu4.20+esm1 | 2 |
| istio/ | dbb7726d1bf0 | openssl | 1.1.1-1ubuntu2.1~18.04.13 | 2 |
| istio/ | a78b7a165744 | openssl | 1.1.1-1ubuntu2.1~18.04.13 | 2 |
| jettech/ | c42098c8d855 | openssl | 1.1.0l-1~deb9u4 | 2 |
| jettech/ | fb7c2cd46ccf | openssl | 1.1.0l-1~deb9u4 | 2 |