StackRadar

CVE-2021-44832

Medium

Advisory

Published 4 Jan 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.6
base score, highest
EPSS
0.979
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
2 of 2
affected packages

Improper Input Validation and Injection in Apache Log4j2

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+13 more2.12.4, 2.17.155
pax-logging-log4j2maven1.11.3, 1.11.4, 1.11.12, 2.0.131.11.13, 2.0.145
OSV records
GHSA-8489-44mv-ggj8

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
pax-logging-log4j2@1.11.4
2.17.1
1.11.13

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
pax-logging-log4j2@1.11.12
2.17.1
1.11.13

Open the chart page →

41,044
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
log4j-core@2.8.2
2.12.4

Open the chart page →

9,606
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.12.4

Open the chart page →

6,907
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.12.4

Open the chart page →

3,164
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-core@2.9.1
2.12.4

Open the chart page →

11,841
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.17.1

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.17.1

Open the chart page →

8,806
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.4

Open the chart page →

4,538
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.4

Open the chart page →

5,460
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.17.1

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
pax-logging-log4j2@1.11.3
2.12.4
1.11.13

Open the chart page →

6,213

Container images carrying it

55 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
pax-logging-log4j2@1.11.12
2.17.1
1.11.13
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.12.4
1
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.12.4
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
log4j-core@2.11.1
2.12.4
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.12.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.