CVE-2021-4279
HighAdvisory
Published 25 Dec 2022In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.3
- base score, highest
- EPSS
- 0.011
- 63rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Starcounter-Jack JSON-Patch Prototype Pollution vulnerability
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| fast-json-patchnpm | 2.2.1, 3.0.0-1, 3.1.0 | 3.1.1 | 7 |
- OSV records
- GHSA-8gh8-hqwg-xf34
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| kobotoolboxone-acre-fundVerified publisher | 0.7.4 | 1 of 9See more | 18,517 |
| shinobigeek-cookbookVerified publisher | 1.2.2 | 1 of 1See more | 4,591 |
| backstageirembo-backstage-helmVerified publisher | 1.0.5 | 1 of 3See more | 7,232 |
| yapijoelee2012Verified publisher | 0.2.0 | 1 of 1See more | 6,454 |
| shinobik8s-home-lab-repo | 2.1.1 | 1 of 1See more | 4,667 |
| codimdphntom | 0.1.12 | 1 of 3See more | 6,524 |
| trudesktechpreta | 1.0.0 | 1 of 3See more | 4,017 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| enketo/ | dcad9c2273f6 | fast-json-patch | 3.1.1 | 1 |
| jayfong/ | 163e5d621910 | fast-json-patch | 3.1.1 | 1 |
| phntom/ | 1b9aafbb62e6 | fast-json-patch | 3.1.1 | 1 |
| polonel/ | 0cf6513f6fe3 | fast-json-patch | 3.1.1 | 1 |
| roadiehq/ | ef355bf5b639 | fast-json-patch | 3.1.1 | 1 |
| shinobisystems/ | 3ca746937856 | fast-json-patch | 3.1.1 | 1 |
| shinobisystems/ | c2f5ce2e1067 | fast-json-patch | 3.1.1 | 1 |