StackRadar

CVE-2021-43618

High

Advisory

Published 15 Nov 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.037
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
715
of 17,787 indexed, latest versions
Container images
691
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: gmp security and enhancement update

Carried by container images the latest versions of 715 of 17,787 indexed charts deploy, on 691 images.

Affected packageAffected versionsFixed inImages
gmpdeb2:5.1.3+dfsg-1ubuntu1, 2:6.1.0+dfsg-2, 2:6.1.2+dfsg-1, 2:6.1.2+dfsg-2+1 more2:5.1.3+dfsg-1ubuntu1+esm1, 2:6.1.0+dfsg-2ubuntu0.1~esm1, 2:6.1.2+dfsg-1+deb9u1, 2:6.1.2+dfsg-2ubuntu0.1+1 more434
gmpapk6.2.0-r0, 6.2.1-r06.2.1-r168
gmprpm1:6.1.2-8.el8, 1:6.1.2-10.el8, 1:6.2.0-10.el9, 6.1.2-4.3.1+1 more1:6.1.2-11.el8, 1:6.1.2-11.el8_6.1, 1:6.1.2-11.el8_8.1, 1:6.2.0-13.el9+2 more189
OSV records
ALPINE-CVE-2021-43618UBUNTU-CVE-2021-43618RHSA-2023:6661RHSA-2024:1102RHSA-2024:1412RHSA-2024:3214DLA-2837-1openSUSE-SU-2024:11636-1SUSE-SU-2021:3946-1
Also known as
USN-5672-1, USN-5672-2

Charts affected

715 by stars
ChartLatestAffected imagesRadar Score
webencryptorwebencryptor1.1.01 of 1See more

webencryptor webencryptor 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
beubi/webencryptor:latesta02c2e200920
gmp@2:6.1.2+dfsg-1
2:6.1.2+dfsg-1+deb9u1

Open the chart page →

1,968
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1

Open the chart page →

14,420
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8

Open the chart page →

28,699
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
gmp@2:6.1.2+dfsg-1
2:6.1.2+dfsg-1+deb9u1

Open the chart page →

10,127
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
gmp@2:6.1.2+dfsg-2
2:6.1.2+dfsg-2ubuntu0.1

Open the chart page →

10,857
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1

Open the chart page →

15,287
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8

Open the chart page →

6,138
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
gmp@6.2.1-r0
6.2.1-r1

Open the chart page →

2,555
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
library/cassandra:3.11.3ce85468c5bad
gmp@2:6.1.2+dfsg-1
2:6.1.2+dfsg-1+deb9u1

Open the chart page →

22,665
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8

Open the chart page →

11,592
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
gmp@6.2.1-r0
6.2.1-r1

Open the chart page →

2,535
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2021-43618.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gmp@2:6.1.2+dfsg-2
2:6.1.2+dfsg-2ubuntu0.1
yandex/clickhouse-server:21.3.204eccfffb01d7
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1

Open the chart page →

9,250

Container images carrying it

691 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
gmp@6.2.0-r0
6.2.1-r1
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/ctron/kubectl:1.25e37d61b5277c
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
gmp@1:6.2.0-10.el9
1:6.2.0-13.el9
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
gmp@2:6.1.2+dfsg-2
2:6.1.2+dfsg-2ubuntu0.1
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
gmp@6.2.1-r0
6.2.1-r1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
gmp@1:6.1.2-10.el8
1:6.1.2-11.el8
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
gmp@2:6.2.0+dfsg-4
2:6.2.0+dfsg-4ubuntu0.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.