StackRadar

CVE-2021-43527

Critical

Advisory

Published 1 Dec 2021In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.176
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
76
of 17,781 indexed, latest versions
Container images
80
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: nss security update

Carried by container images the latest versions of 76 of 17,781 indexed charts deploy, on 80 images.

Affected packageAffected versionsFixed inImages
nssdeb2:3.17.1-0ubuntu0.14.04.1, 2:3.26.2-1.1, 2:3.26.2-1.1+deb9u1, 2:3.28.4-0ubuntu0.14.04.3+11 more2:3.26.2-1.1+deb9u3, 2:3.28.4-0ubuntu0.14.04.5+esm10, 2:3.28.4-0ubuntu0.16.04.14+esm2, 2:3.35-2ubuntu2.13+2 more48
nssrpm3.36.0-7.1.el7_6, 3.44.0-4.el7, 3.44.0-7.el7_7, 3.53.1-3.el7_9+2 more0:3.67.0-4.el7_9, 0:3.67.0-7.el8_531
nssapk3.60-r03.60-r21
OSV records
ALPINE-CVE-2021-43527RHSA-2021:4903RHSA-2021:4904UBUNTU-CVE-2021-43527DLA-2836-1DSA-5016-1
Also known as
RHSA-2021:4909, RHSA-2021:4933, RHSA-2021:4946, USN-5168-1, USN-5168-3, USN-5168-4

Charts affected

76 by stars
ChartLatestAffected imagesRadar Score
ibm-open-libertyibm-charts1.10.01 of 1See more

ibm-open-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
nss@3.44.0-4.el7
0:3.67.0-4.el7_9

Open the chart page →

2,063
ibm-open-liberty-springibm-charts1.10.01 of 1See more

ibm-open-liberty-spring ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
nss@3.44.0-4.el7
0:3.67.0-4.el7_9

Open the chart page →

2,063
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
nss@3.44.0-7.el7_7
0:3.67.0-4.el7_9

Open the chart page →

4,505
ibm-websphere-libertyibm-charts1.10.01 of 1See more

ibm-websphere-liberty ibm-charts 1.10.0

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
nss@3.44.0-4.el7
0:3.67.0-4.el7_9

Open the chart page →

2,063
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
nss@2:3.26.2-1.1
2:3.26.2-1.1+deb9u3

Open the chart page →

10,682
helm-controllerkubedex0.4.01 of 1See more

helm-controller kubedex 0.4.0

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
kubedex/helm-controller:v1.0.14f1008c51ef9
nss@3.36.0-7.1.el7_6
0:3.67.0-4.el7_9

Open the chart page →

2,422
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
nss@2:3.49.1-1ubuntu1.5
2:3.49.1-1ubuntu1.6

Open the chart page →

25,933
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

4,911
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
ncsapolyglot/converters-avconv:latestc44b22eb58bb
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

55,726
zookeeper-helm-chartnotesprojectchart0.1.01 of 1See more

zookeeper-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
nss@2:3.17.1-0ubuntu0.14.04.1
2:3.28.4-0ubuntu0.14.04.5+esm10

Open the chart page →

41,427
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
nss@2:3.35-2ubuntu2.7
2:3.35-2ubuntu2.13

Open the chart page →

27,633
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
nss@2:3.35-2ubuntu2.2
2:3.35-2ubuntu2.13

Open the chart page →

63,223
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
library/cassandra:2.1.20cb079c0d7a57
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

40,715
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
nss@2:3.28.4-0ubuntu0.14.04.3
2:3.28.4-0ubuntu0.14.04.5+esm10

Open the chart page →

26,339
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5

Open the chart page →

29,227
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022022 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

2 of the 2 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
nss@3.67.0-3.el7_9
0:3.67.0-4.el7_9

Open the chart page →

5,942
rke2-kube-proxyrke2-charts1.20.21 of 1See more

rke2-kube-proxy rke2-charts 1.20.2

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
rancher/hardened-kube-proxy:v1.20.2d0600143c23c
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9

Open the chart page →

1,552
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5

Open the chart page →

28,165
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

11,841
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
nss@3.67.0-3.el7_9
0:3.67.0-4.el7_9
altinity/metrics-exporter:0.16.185b4fdbae053
nss@3.67.0-3.el7_9
0:3.67.0-4.el7_9

Open the chart page →

8,707
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

21,005
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5

Open the chart page →

12,455
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nss@2:3.49.1-1ubuntu1.5
2:3.49.1-1ubuntu1.6

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nss@2:3.49.1-1ubuntu1.5
2:3.49.1-1ubuntu1.6
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-43527.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3

Open the chart page →

22,665

Container images carrying it

80 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
openzipkin/zipkin-dependencies:2.6.45ff2fa849a82
nss@3.60-r0
3.60-r2
1
opsmx11/issuegen:v2.1.05c50ca123d88
nss@2:3.28.4-0ubuntu0.14.04.3
2:3.28.4-0ubuntu0.14.04.5+esm10
1
pedrocesarti/jmeter-docker:3.314851f144f57
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3
1
rancher/hardened-calico:v3.13.36d2cd61a338b
nss@3.44.0-7.el7_7
0:3.67.0-4.el7_9
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9
1
rancher/hardened-cni-plugins:v0.9.1-build20210414be3c1d469bf7
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
nss@3.67.0-3.el7_9
0:3.67.0-4.el7_9
1
rancher/hardened-kube-proxy:v1.20.2d0600143c23c
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
nss@3.53.1-3.el7_9
0:3.67.0-4.el7_9
1
raykrueger/riemann:0.2.14c8baf3de57bb
nss@2:3.26.2-1.1
2:3.26.2-1.1+deb9u3
1
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
nss@2:3.26.2-1.1
2:3.26.2-1.1+deb9u3
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
nss@2:3.26.2-1.1
2:3.26.2-1.1+deb9u3
1
rundeck/rundeck:3.2.74d64fe56f767
nss@2:3.28.4-0ubuntu0.16.04.10
2:3.28.4-0ubuntu0.16.04.14+esm2
1
rundeck/rundeck:3.0.16b13e8059ad72
nss@2:3.28.4-0ubuntu0.16.04.4
2:3.28.4-0ubuntu0.16.04.14+esm2
1
scrapinghub/splash:3.4.1a5f89bc84606
nss@2:3.35-2ubuntu2.7
2:3.35-2ubuntu2.13
1
sinusbot/docker:1.0.0-beta.14-dc94a7cc7a4f3cc4393
nss@2:3.42.1-1+deb10u3
2:3.42.1-1+deb10u4
1
sismics/docs:v1.10f4b0ef019cf1
nss@2:3.35-2ubuntu2.12
2:3.35-2ubuntu2.13
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
nss@2:3.28.4-0ubuntu0.16.04.3
2:3.28.4-0ubuntu0.16.04.14+esm2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
nss@2:3.28.4-0ubuntu0.16.04.3
2:3.28.4-0ubuntu0.16.04.14+esm2
1
wavefronthq/proxy:9.2d1064d28f6eb
nss@2:3.35-2ubuntu2.11
2:3.35-2ubuntu2.13
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
nss@2:3.49.1-1ubuntu1.5
2:3.49.1-1ubuntu1.6
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
nss@2:3.49.1-1ubuntu1.5
2:3.49.1-1ubuntu1.6
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
nss@2:3.42.1-1+deb10u3
2:3.42.1-1+deb10u4
1
ghcr.io/kvaps/linstor-satellite:v1.14.0a573fb9bc809
nss@2:3.42.1-1+deb10u3
2:3.42.1-1+deb10u4
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
nss@2:3.26.2-1.1+deb9u1
2:3.26.2-1.1+deb9u3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
nss@2:3.28.4-0ubuntu0.16.04.6
2:3.28.4-0ubuntu0.16.04.14+esm2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nss@3.53.1-17.el8_3
0:3.67.0-7.el8_5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.