StackRadar

CVE-2021-38153

Medium

Advisory

Published 23 Sept 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.063
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
30
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
3 of 4
affected packages

Timing Attack Vulnerability for Apache Kafka Connect and Clients

Carried by container images the latest versions of 30 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven2.0.0, 2.0.1, 2.0.1-cp1, 2.2.0+8 more2.6.3, 2.7.224
kafka_2.11maven2.0.0, 2.0.1-cp1, 2.4.0no fix listed3
kafkabitnami2.8.1-1502.6.31
kafka_2.12maven2.5.12.6.31
OSV records
BIT-kafka-2021-38153GHSA-3j6g-hxx5-3q26

Charts affected

30 by stars
ChartLatestAffected imagesRadar Score
zipkincarlosjgp0.2.01 of 2See more

zipkin carlosjgp 0.2.0

1 of the 2 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
openzipkin/zipkin:2.21.060c3970df479
kafka-clients@2.4.1
2.6.3

Open the chart page →

3,229
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
kafka_2.11@2.0.0
kafka-clients@2.0.0
no fix listed
2.6.3

Open the chart page →

7,930
cloudflowcloudflow-helm-charts0.0.0-NIGHTLY011220201 of 1See more

cloudflow cloudflow-helm-charts 0.0.0-NIGHTLY01122020

1 of the 1 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
kafka-clients@2.5.0
2.6.3

Open the chart page →

1,886
cmak-operatorcmak-operatorVerified publisher2.2.21 of 3See more

cmak-operator cmak-operator 2.2.2

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
kafka-clients@2.4.1
2.6.3

Open the chart page →

4,605
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
kafka-clients@2.4.1
2.6.3

Open the chart page →

18,042
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
kafka-clients@2.5.0
2.6.3

Open the chart page →

10,730
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
kafka_2.12@2.5.1
kafka-clients@2.5.1
2.6.3
2.6.3

Open the chart page →

7,529
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
2.6.3

Open the chart page →

5,806
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
kafka_2.11@2.0.1-cp1
kafka-clients@2.0.1-cp1
no fix listed
2.6.3

Open the chart page →

12,018
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
kafka_2.11@2.4.0
kafka-clients@2.4.0
no fix listed
2.6.3

Open the chart page →

8,245
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
2.6.3

Open the chart page →

12,513
scorpio-brokerfiware0.3.31 of 10See more

scorpio-broker fiware 0.3.3

1 of the 10 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
kafka-clients@2.0.1
2.6.3

Open the chart page →

55,600
scorpiobrokerfiware0.1.21 of 10See more

scorpiobroker fiware 0.1.2

1 of the 10 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
kafka-clients@2.0.1
2.6.3

Open the chart page →

55,600
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
kafka-clients@2.2.1
2.6.3

Open the chart page →

15,722
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
kafka-clients@2.4.1
2.6.3

Open the chart page →

16,401
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
kafka-clients@2.4.1
2.6.3

Open the chart page →

20,650
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
kafka-clients@2.0.1
2.6.3

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
kafka-clients@2.5.0
2.6.3

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
kafka-clients@2.5.0
2.6.3

Open the chart page →

10,603
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
kafka@2.8.1-150
2.6.3

Open the chart page →

16,198
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
kafka-clients@2.2.0
2.6.3

Open the chart page →

63,223
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
kafka-clients@2.4.0
2.6.3

Open the chart page →

36,215
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
2.6.3

Open the chart page →

12,513
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
kafka-clients@2.4.1
2.6.3

Open the chart page →

13,767
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
kafka-clients@2.3.0
2.6.3

Open the chart page →

4,538
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
2.6.3

Open the chart page →

12,513
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
2.7.2

Open the chart page →

12,455
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
2.7.2

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
2.6.3

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-38153.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
2.6.3

Open the chart page →

5,806

Container images carrying it

25 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
2.6.3
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
2.6.3
2
opensearchproject/opensearch:1.1.0967d7f57f72f
kafka-clients@2.5.0
2.6.3
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
kafka-clients@2.0.1
2.6.3
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
kafka-clients@2.0.1
2.6.3
1
anguda/ant-media:2.5c435285fc241
kafka-clients@2.2.1
2.6.3
1
apache/druid:29.0.10cef139b6bf1
kafka_2.11@2.0.0
kafka-clients@2.0.0
no fix listed
2.6.3
1
apache/skywalking-oap-server:9.2.0133d35d2c263
kafka-clients@2.4.1
2.6.3
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
kafka-clients@2.4.1
2.6.3
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
kafka-clients@2.4.1
2.6.3
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
2.6.3
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
2.7.2
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
kafka-clients@2.5.0
2.6.3
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
kafka@2.8.1-150
2.6.3
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
kafka_2.11@2.0.1-cp1
kafka-clients@2.0.1-cp1
no fix listed
2.6.3
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
kafka_2.11@2.4.0
kafka-clients@2.4.0
no fix listed
2.6.3
1
library/logstash:7.17.817a4f64e9cf5
kafka_2.12@2.5.1
kafka-clients@2.5.1
2.6.3
2.6.3
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
kafka-clients@2.5.0
2.6.3
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
kafka-clients@2.2.0
2.6.3
1
openwhisk/invoker:1.0.0f5831ec85525
kafka-clients@2.4.0
2.6.3
1
openzipkin/zipkin:2.21.060c3970df479
kafka-clients@2.4.1
2.6.3
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
kafka-clients@2.3.0
2.6.3
1
trinodb/trino:405ee80ab5eeab2
kafka-clients@2.4.1
2.6.3
1
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
kafka-clients@2.4.1
2.6.3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
2.7.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.