StackRadar

CVE-2021-4104

High

Advisory

Published 14 Dec 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.811
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
100
of 17,781 indexed, latest versions
Container images
101
deployed by those charts
Fix available
None
affected package

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data

Carried by container images the latest versions of 100 of 17,781 indexed charts deploy, on 101 images.

Affected packageAffected versionsFixed inImages
log4jmaven1.2.8, 1.2.14, 1.2.15, 1.2.16+1 moreno fix listed101
OSV records
GHSA-fp5r-v3w9-4333

Charts affected

100 by stars
ChartLatestAffected imagesRadar Score
hdfsgradiant-bigdataVerified publisher0.1.102 of 2See more

hdfs gradiant-bigdata 0.1.10

2 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
log4j@1.2.17
no fix listed
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
log4j@1.2.17
no fix listed

Open the chart page →

7,073
hivegradiant-bigdataVerified publisher0.1.64 of 5See more

hive gradiant-bigdata 0.1.6

4 of the 5 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j@1.2.17
no fix listed
gradiant/hdfs:2.7.73b28784ba41f
log4j@1.2.17
no fix listed
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j@1.2.17
no fix listed
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
log4j@1.2.17
no fix listed

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j@1.2.17
no fix listed

Open the chart page →

6,882
opentsdbgradiant-bigdataVerified publisher0.1.73 of 6See more

opentsdb gradiant-bigdata 0.1.7

3 of the 6 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
log4j@1.2.17
no fix listed
gradiant/hdfs:2.7.73b28784ba41f
log4j@1.2.17
no fix listed
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
log4j@1.2.17
no fix listed

Open the chart page →

17,511
spark-standalonegradiant-bigdataVerified publisher0.1.01 of 2See more

spark-standalone gradiant-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
log4j@1.2.17
no fix listed

Open the chart page →

6,147
siembolgresearch0.1.62 of 4See more

siembol gresearch 0.1.6

2 of the 4 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
log4j@1.2.17
no fix listed
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
log4j@1.2.17
no fix listed

Open the chart page →

14,312
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
log4j@1.2.17
no fix listed

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
log4j@1.2.17
no fix listed

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
log4j@1.2.17
no fix listed

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
log4j@1.2.17
no fix listed

Open the chart page →

4,547
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
log4j@1.2.17
no fix listed

Open the chart page →

8,541
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
log4j@1.2.17
no fix listed

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
log4j@1.2.17
no fix listed

Open the chart page →

8,221
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
log4j@1.2.8
no fix listed

Open the chart page →

19,295
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
log4j@1.2.17
no fix listed

Open the chart page →

6,174
pinotinseefrlab0.2.02 of 2See more

pinot inseefrlab 0.2.0

2 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
log4j@1.2.17
no fix listed
library/zookeeper:3.5.5b7a76ec06f68
log4j@1.2.17
no fix listed

Open the chart page →

10,777
clickhousekubesphere-testVerified publisher0.1.11 of 2See more

clickhouse kubesphere-test 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
radondb/zookeeper:3.6.216981604f1a0
log4j@1.2.17
no fix listed

Open the chart page →

6,696
imageboxkyso1.0.01 of 1See more

imagebox kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
kyso/imagebox:latest68091eace89c
log4j@1.2.17
no fix listed

Open the chart page →

3,833
kafka-connect-wrapperlsmhun0.1.01 of 1See more

kafka-connect-wrapper lsmhun 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
log4j@1.2.17
no fix listed

Open the chart page →

2,391
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j@1.2.17
no fix listed

Open the chart page →

15,855
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
log4j@1.2.17
no fix listed

Open the chart page →

43,341
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
log4j@1.2.17
no fix listed

Open the chart page →

16,198
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
log4j@1.2.17
no fix listed

Open the chart page →

4,989
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
log4j@1.2.17
no fix listed

Open the chart page →

4,911
polyglotncsaVerified publisher0.1.114 of 18See more

polyglot ncsa 0.1.1

14 of the 18 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
log4j@1.2.16
no fix listed
ncsapolyglot/converters-avconv:latestc44b22eb58bb
log4j@1.2.8
no fix listed
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
log4j@1.2.8
no fix listed
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
log4j@1.2.8
no fix listed
ncsapolyglot/converters-flac:latest072cf5bc6f99
log4j@1.2.8
no fix listed
ncsapolyglot/converters-gdal:latestf746049515c1
log4j@1.2.8
no fix listed
ncsapolyglot/converters-ghostscript:latestf350da56dd55
log4j@1.2.8
no fix listed
ncsapolyglot/converters-htmldoc:latest317dd9e56922
log4j@1.2.8
no fix listed
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
log4j@1.2.8
no fix listed
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
log4j@1.2.8
no fix listed
ncsapolyglot/converters-txt2html:latest30ee96508c0b
log4j@1.2.8
no fix listed
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
log4j@1.2.8
no fix listed
ncsapolyglot/converters-zip:latestf889fe30e2c7
log4j@1.2.8
no fix listed
ncsapolyglot/polyglot:2.4.097a8c01c076e
log4j@1.2.8
no fix listed

Open the chart page →

55,726
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
log4j@1.2.17
no fix listed

Open the chart page →

4,547
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
log4j@1.2.15
no fix listed

Open the chart page →

41,427
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
log4j@1.2.17
no fix listed

Open the chart page →

8,540
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
log4j@1.2.16
no fix listed

Open the chart page →

88,546
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
log4j@1.2.16
no fix listed

Open the chart page →

42,614
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
log4j@1.2.16
no fix listed

Open the chart page →

38,865
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
log4j@1.2.8
no fix listed

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
log4j@1.2.8
no fix listed

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
log4j@1.2.8
no fix listed

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
log4j@1.2.8
no fix listed

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
log4j@1.2.8
no fix listed

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
log4j@1.2.8
no fix listed

Open the chart page →

13,100
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
library/zookeeper:3.43882d9493d38
log4j@1.2.15
no fix listed

Open the chart page →

36,215
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
log4j@1.2.17
no fix listed

Open the chart page →

6,237
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
log4j@1.2.17
no fix listed

Open the chart page →

9,606
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
log4j@1.2.17
no fix listed

Open the chart page →

8,098
sentry-dbsentry0.9.41 of 10See more

sentry-db sentry 0.9.4

1 of the 10 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.4.01bbda887bc53
log4j@1.2.17
no fix listed

Open the chart page →

10,967
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
log4j@1.2.17
no fix listed

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
log4j@1.2.17
no fix listed

Open the chart page →

13,079
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j@1.2.17
no fix listed

Open the chart page →

3,164
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
library/zookeeper:3.5.5b7a76ec06f68
log4j@1.2.17
no fix listed

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
log4j@1.2.17
no fix listed

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
log4j@1.2.17
no fix listed

Open the chart page →

8,554
clickhousetemp-charts0.7.11 of 3See more

clickhouse temp-charts 0.7.1

1 of the 3 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
library/zookeeper:3.6.180ad2170ad62
log4j@1.2.17
no fix listed

Open the chart page →

8,707
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2021-4104.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j@1.2.17
no fix listed

Open the chart page →

6,213

Container images carrying it

101 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j@1.2.17
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.