StackRadar

CVE-2021-40690

High

Advisory

Published 20 Sept 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.074
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
32
of 17,781 indexed, latest versions
Container images
30
deployed by those charts
Fix available
1 of 1
affected package

Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario

Carried by container images the latest versions of 32 of 17,781 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
xmlsecmaven1.5.6, 1.5.8, 2.0.7, 2.0.8+4 more2.1.7, 2.2.330
OSV records
GHSA-j8wc-gxx9-82hx

Charts affected

32 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
xmlsec@2.1.4
2.1.7

Open the chart page →

6,556
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
xmlsec@2.1.4
2.1.7

Open the chart page →

4,099
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
xmlsec@2.1.4
2.1.7
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
xmlsec@2.1.4
2.1.7

Open the chart page →

8,698
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
xmlsec@2.1.4
2.1.7

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
xmlsec@2.2.0
2.2.3

Open the chart page →

10,730
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
xmlsec@2.1.4
2.1.7

Open the chart page →

38,346
elasticsearch-dataempathyco0.2.01 of 2See more

elasticsearch-data empathyco 0.2.0

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
xmlsec@2.0.8
2.1.7

Open the chart page →

3,703
elasticsearch-masterempathyco0.3.01 of 2See more

elasticsearch-master empathyco 0.3.0

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
xmlsec@2.0.8
2.1.7

Open the chart page →

3,703
amgraviteeioVerified publisher4.12.62 of 3See more

am graviteeio 4.12.6

2 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
graviteeio/am-gateway:4.12.607b7f6dc267a
xmlsec@2.1.4
2.1.7
graviteeio/am-management-api:4.12.6a8eb04ee0c70
xmlsec@2.1.4
2.1.7

Open the chart page →

2,088
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
xmlsec@2.1.4
2.1.7

Open the chart page →

17,284
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
xmlsec@2.1.4
2.1.7

Open the chart page →

31,844
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
xmlsec@1.5.8
2.1.7

Open the chart page →

3,958
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
xmlsec@2.1.4
2.1.7

Open the chart page →

6,045
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
xmlsec@2.2.0
2.2.3

Open the chart page →

5,806
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
xmlsec@2.1.4
2.1.7

Open the chart page →

10,564
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.1588c2ec10c7f2
xmlsec@2.1.4
2.1.7

Open the chart page →

34,754
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
xmlsec@2.0.7
2.1.7

Open the chart page →

39,349
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
xmlsec@2.1.4
2.1.7

Open the chart page →

12,856
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
xmlsec@2.0.7
2.1.7

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
xmlsec@2.2.0
2.2.3

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
xmlsec@2.2.0
2.2.3

Open the chart page →

10,603
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
xmlsec@2.1.4
2.1.7

Open the chart page →

9,300
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
xmlsec@2.1.5
2.1.7

Open the chart page →

6,237
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
reportportal/service-authorization:5.7.09e73114dbd15
xmlsec@2.1.5
2.1.7

Open the chart page →

25,737
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
xmlsec@2.0.7
2.1.7

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
xmlsec@1.5.6
2.1.7

Open the chart page →

13,079
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
xmlsec@2.1.5
2.1.7

Open the chart page →

12,455
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
xmlsec@2.1.4
2.1.7

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
xmlsec@2.1.6
2.1.7

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
xmlsec@2.1.5
2.1.7

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
xmlsec@2.2.0
2.2.3

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2021-40690.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
xmlsec@2.1.5
2.1.7

Open the chart page →

6,213

Container images carrying it

30 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
xmlsec@2.2.0
2.2.3
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
xmlsec@2.0.8
2.1.7
2
library/elasticsearch:7.17.35e6ac15bf6a5
xmlsec@2.1.4
2.1.7
2
opensearchproject/opensearch:1.1.0967d7f57f72f
xmlsec@2.2.0
2.2.3
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
xmlsec@2.0.7
2.1.7
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
xmlsec@2.1.5
2.1.7
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
xmlsec@2.1.5
2.1.7
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
xmlsec@2.2.0
2.2.3
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
xmlsec@2.1.4
2.1.7
1
atlassian/confluence-server:7.10.03b9222ab32ef
xmlsec@2.0.7
2.1.7
1
atlassian/jira-software:8.14.037bc46cbec1a
xmlsec@1.5.6
2.1.7
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
xmlsec@2.1.4
2.1.7
1
farberg/apache-knox-docker:1.6.14b4a22487394
xmlsec@2.1.5
2.1.7
1
graviteeio/am-gateway:4.12.607b7f6dc267a
xmlsec@2.1.4
2.1.7
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
xmlsec@2.1.4
2.1.7
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
xmlsec@2.0.7
2.1.7
1
library/elasticsearch:7.17.0332c6d416808
xmlsec@2.1.4
2.1.7
1
library/elasticsearch:7.17.1588c2ec10c7f2
xmlsec@2.1.4
2.1.7
1
library/elasticsearch:7.17.8fdc73b3249c1
xmlsec@2.1.4
2.1.7
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
xmlsec@2.1.4
2.1.7
1
library/sonarqube:8.9.2-community88cd63154d4b
xmlsec@2.1.4
2.1.7
1
library/sonarqube:8.2-communitya246bc64207e
xmlsec@2.1.4
2.1.7
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
xmlsec@2.1.4
2.1.7
1
library/sonarqube:10.0.0-communityef9723cf4fe4
xmlsec@2.1.4
2.1.7
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
xmlsec@2.1.5
2.1.7
1
remche/shinyproxy:2.6.18bcda8a04d3b
xmlsec@1.5.8
2.1.7
1
reportportal/service-authorization:5.7.09e73114dbd15
xmlsec@2.1.5
2.1.7
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
xmlsec@2.1.4
2.1.7
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
xmlsec@2.1.4
2.1.7
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
xmlsec@2.1.6
2.1.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.