CVE-2021-43527
CriticalAdvisory
Published 1 Dec 2021In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.176
- 97th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 76
- of 17,781 indexed, latest versions
- Container images
- 80
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Red Hat Security Advisory: nss security update
Carried by container images the latest versions of 76 of 17,781 indexed charts deploy, on 80 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nssdeb | 2:3.17.1-0ubuntu0.14.04.1, 2:3.26.2-1.1, 2:3.26.2-1.1+deb9u1, 2:3.28.4-0ubuntu0.14.04.3+11 more | 2:3.26.2-1.1+deb9u3, 2:3.28.4-0ubuntu0.14.04.5+esm10, 2:3.28.4-0ubuntu0.16.04.14+esm2, 2:3.35-2ubuntu2.13+2 more | 48 |
| nssrpm | 3.36.0-7.1.el7_6, 3.44.0-4.el7, 3.44.0-7.el7_7, 3.53.1-3.el7_9+2 more | 0:3.67.0-4.el7_9, 0:3.67.0-7.el8_5 | 31 |
| nssapk | 3.60-r0 | 3.60-r2 | 1 |
- OSV records
- ALPINE-CVE-2021-43527RHSA-2021:4903RHSA-2021:4904UBUNTU-CVE-2021-43527DLA-2836-1DSA-5016-1
- Also known as
- RHSA-2021:4909, RHSA-2021:4933, RHSA-2021:4946, USN-5168-1, USN-5168-3, USN-5168-4
Charts affected
76 by stars
Container images carrying it
80 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| openzipkin/ | 5ff2fa849a82 | nss | 3.60-r2 | 1 |
| opsmx11/ | 5c50ca123d88 | nss | 2:3.28.4-0ubuntu0.14.04.5+esm10 | 1 |
| pedrocesarti/ | 14851f144f57 | nss | 2:3.26.2-1.1+deb9u3 | 1 |
| rancher/ | 6d2cd61a338b | nss | 0:3.67.0-4.el7_9 | 1 |
| rancher/ | c678c25d47c8 | nss | 0:3.67.0-4.el7_9 | 1 |
| rancher/ | be3c1d469bf7 | nss | 0:3.67.0-4.el7_9 | 1 |
| rancher/ | 42784bb38ed3 | nss | 0:3.67.0-4.el7_9 | 1 |
| rancher/ | d6a47d394c03 | nss | 0:3.67.0-4.el7_9 | 1 |
| rancher/ | d0600143c23c | nss | 0:3.67.0-4.el7_9 | 1 |
| rancher/ | 8eb8092f0728 | nss | 0:3.67.0-4.el7_9 | 1 |
| raykrueger/ | c8baf3de57bb | nss | 2:3.26.2-1.1+deb9u3 | 1 |
| richardchesterwood/ | 0b540a28f5a6 | nss | 2:3.26.2-1.1+deb9u3 | 1 |
| richardchesterwood/ | 36c43961214c | nss | 2:3.26.2-1.1+deb9u3 | 1 |
| rundeck/ | 4d64fe56f767 | nss | 2:3.28.4-0ubuntu0.16.04.14+esm2 | 1 |
| rundeck/ | b13e8059ad72 | nss | 2:3.28.4-0ubuntu0.16.04.14+esm2 | 1 |
| scrapinghub/ | a5f89bc84606 | nss | 2:3.35-2ubuntu2.13 | 1 |
| sinusbot/ | c7a4f3cc4393 | nss | 2:3.42.1-1+deb10u4 | 1 |
| sismics/ | f4b0ef019cf1 | nss | 2:3.35-2ubuntu2.13 | 1 |
| tensorflow/ | 1e3172090703 | nss | 2:3.28.4-0ubuntu0.16.04.14+esm2 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | nss | 2:3.28.4-0ubuntu0.16.04.14+esm2 | 1 |
| wavefronthq/ | d1064d28f6eb | nss | 2:3.35-2ubuntu2.13 | 1 |
| ghcr.io/ | cbd5d4cc1245 | nss | 2:3.49.1-1ubuntu1.6 | 1 |
| ghcr.io/ | ef3670f7e0a8 | nss | 2:3.49.1-1ubuntu1.6 | 1 |
| ghcr.io/ | 00ce11c31087 | nss | 2:3.42.1-1+deb10u4 | 1 |
| ghcr.io/ | a573fb9bc809 | nss | 2:3.42.1-1+deb10u4 | 1 |
| quay.io/ | a3b9a07648b6 | nss | 0:3.67.0-7.el8_5 | 1 |
| quay.io/ | 01c3b7acb301 | nss | 2:3.26.2-1.1+deb9u3 | 1 |
| quay.io/ | 3029dc0f1d38 | nss | 0:3.67.0-7.el8_5 | 1 |
| quay.io/ | c6a934439421 | nss | 2:3.28.4-0ubuntu0.16.04.14+esm2 | 1 |
| quay.io/ | 6ba82beff18e | nss | 0:3.67.0-7.el8_5 | 1 |