StackRadar

CVE-2021-44832

Medium

Advisory

Published 4 Jan 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.6
base score, highest
EPSS
0.979
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
2 of 2
affected packages

Improper Input Validation and Injection in Apache Log4j2

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+13 more2.12.4, 2.17.155
pax-logging-log4j2maven1.11.3, 1.11.4, 1.11.12, 2.0.131.11.13, 2.0.145
OSV records
GHSA-8489-44mv-ggj8

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
pax-logging-log4j2@1.11.4
2.17.1
1.11.13

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
log4j-core@2.17.0
pax-logging-log4j2@1.11.12
2.17.1
1.11.13

Open the chart page →

41,044
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
log4j-core@2.8.2
2.12.4

Open the chart page →

9,606
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.12.4

Open the chart page →

6,907
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.12.4

Open the chart page →

3,164
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-core@2.9.1
2.12.4

Open the chart page →

11,841
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.17.1

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.17.1

Open the chart page →

8,806
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.4

Open the chart page →

4,538
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.4

Open the chart page →

5,460
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.17.1

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2021-44832.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
pax-logging-log4j2@1.11.3
2.12.4
1.11.13

Open the chart page →

6,213

Container images carrying it

55 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.4
4
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.17.1
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.17.1
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j-core@2.10.0
2.12.4
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
log4j-core@2.11.1
2.12.4
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j-core@2.6.2
2.12.4
2
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-core@2.14.0
2.17.1
2
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.17.1
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.12.4
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
log4j-core@2.11.1
2.12.4
1
apacheignite/ignite:2.7.0d7deab68b8fa
log4j-core@2.11.0
2.12.4
1
apachepulsar/pulsar:2.6.14db6ff0b4045
log4j-core@2.10.0
2.12.4
1
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-core@2.14.0
2.17.1
1
apachepulsar/pulsar:2.8.2d538416d5afe
log4j-core@2.17.0
2.17.1
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
log4j-core@2.9.0
2.12.4
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
log4j-core@2.15.0
2.17.1
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
log4j-core@2.13.0
2.17.1
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
log4j-core@2.11.1
2.12.4
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
log4j-core@2.17.0
pax-logging-log4j2@1.11.12
2.17.1
1.11.13
1
datappeal/hive-metastore:lateste38c085a3567
log4j-core@2.8.2
2.12.4
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
log4j-core@2.11.1
2.12.4
1
emeraldpay/dshackle:0.14.0126f0ae0b388
log4j-core@2.17.0
2.17.1
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
log4j-core@2.17.0
2.17.1
1
folioci/mod-aes:latest6d67e9564270
log4j-core@2.14.1
2.17.1
1
folioci/mod-marccat:latest1b57d690d568
log4j-core@2.10.0
2.12.4
1
fonoster/routr:1.0.0-rc52ca65af17cbc
log4j-core@2.11.0
2.12.4
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-core@2.13.3
2.17.1
1
graylog2/server:2.4.3-38ff28c66e6c1
log4j-core@2.9.1
2.12.4
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
log4j-core@2.17.0
2.17.1
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
log4j-core@2.11.2
2.12.4
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
log4j-core@2.11.1
2.12.4
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
log4j-core@2.11.1
2.12.4
1
ibmcom/microclimate-portal:latested5505e5c7ec
log4j-core@2.8.2
2.12.4
1
jacobalberty/unifi:5.10.19c409924e2463
log4j-core@2.11.1
2.12.4
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-core@2.12.1
2.12.4
1
library/neo4j:4.2.4348e3f56faa2
log4j-core@2.14.0
2.17.1
1
library/solr:8.7.0d124efd81fbb
log4j-core@2.13.2
2.17.1
1
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-core@2.9.1
2.12.4
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
log4j-core@2.11.1
2.12.4
1
library/sonarqube:8.9.2-community88cd63154d4b
log4j-core@2.11.1
2.12.4
1
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.4
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
log4j-core@2.11.1
2.12.4
1
library/sonarqube:8.9-communityeb2f0be32efd
log4j-core@2.17.0
2.17.1
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
pax-logging-log4j2@1.11.3
2.12.4
1.11.13
1
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
pax-logging-log4j2@1.11.4
2.17.1
1.11.13
1
openhab/openhab:3.2.0d0aa4af452c1
log4j-core@2.17.0
pax-logging-log4j2@2.0.13
2.17.1
2.0.14
1
openzipkin/zipkin:2.21.060c3970df479
log4j-core@2.12.1
2.12.4
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.4
1
pedrocesarti/jmeter-docker:3.314851f144f57
log4j-core@2.8.2
2.12.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
log4j-core@2.6.2
2.12.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.