StackRadar

CVE-2021-45105

High

Advisory

Published 18 Dec 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
47
deployed by those charts
Fix available
2 of 2
affected packages

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 47 images.

Affected packageAffected versionsFixed inImages
log4j-coremaven2.6.2, 2.8.2, 2.9.0, 2.9.1+12 more2.12.3, 2.17.047
pax-logging-log4j2maven1.11.3, 1.11.41.11.122
OSV records
GHSA-p6xc-xr62-6r2g

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
zipkin-gcpt3n1.0.01 of 1See more

zipkin-gcp t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-45105.

Container imageDigestPackageFixed in
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.3

Open the chart page →

4,538
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2021-45105.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.3

Open the chart page →

5,460
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-45105.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.17.0

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2021-45105.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
pax-logging-log4j2@1.11.3
2.12.3
1.11.12

Open the chart page →

6,213

Container images carrying it

47 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
log4j-core@2.6.2
2.12.3
4
library/solr:8.11.18c5f7881cebb
log4j-core@2.16.0
2.17.0
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
log4j-core@2.13.0
2.17.0
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
log4j-core@2.10.0
2.12.3
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
log4j-core@2.11.1
2.12.3
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
log4j-core@2.6.2
2.12.3
2
library/neo4j:4.3.2-enterprise56a9453c4064
log4j-core@2.14.0
2.17.0
2
opensearchproject/opensearch:1.1.0967d7f57f72f
log4j-core@2.13.0
2.17.0
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
log4j-core@2.11.2
2.12.3
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
log4j-core@2.11.1
2.12.3
1
apacheignite/ignite:2.7.0d7deab68b8fa
log4j-core@2.11.0
2.12.3
1
apachepulsar/pulsar:2.6.14db6ff0b4045
log4j-core@2.10.0
2.12.3
1
apachepulsar/pulsar:2.9.0d056c89b7131
log4j-core@2.14.0
2.17.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
log4j-core@2.9.0
2.12.3
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
log4j-core@2.15.0
2.17.0
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
log4j-core@2.13.0
2.17.0
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
log4j-core@2.11.1
2.12.3
1
datappeal/hive-metastore:lateste38c085a3567
log4j-core@2.8.2
2.12.3
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
log4j-core@2.11.1
2.12.3
1
folioci/mod-aes:latest6d67e9564270
log4j-core@2.14.1
2.17.0
1
folioci/mod-marccat:latest1b57d690d568
log4j-core@2.10.0
2.12.3
1
fonoster/routr:1.0.0-rc52ca65af17cbc
log4j-core@2.11.0
2.12.3
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
log4j-core@2.13.3
2.17.0
1
graylog2/server:2.4.3-38ff28c66e6c1
log4j-core@2.9.1
2.12.3
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
log4j-core@2.11.2
2.12.3
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
log4j-core@2.11.1
2.12.3
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
log4j-core@2.11.1
2.12.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
log4j-core@2.8.2
2.12.3
1
jacobalberty/unifi:5.10.19c409924e2463
log4j-core@2.11.1
2.12.3
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
log4j-core@2.12.1
2.12.3
1
library/neo4j:4.2.4348e3f56faa2
log4j-core@2.14.0
2.17.0
1
library/solr:8.7.0d124efd81fbb
log4j-core@2.13.2
2.17.0
1
library/sonarqube:6.7.6-community0ae5169e3d0f
log4j-core@2.9.1
2.12.3
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
log4j-core@2.11.1
2.12.3
1
library/sonarqube:8.9.2-community88cd63154d4b
log4j-core@2.11.1
2.12.3
1
library/sonarqube:8.2-communitya246bc64207e
log4j-core@2.11.1
2.12.3
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
log4j-core@2.11.1
2.12.3
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
log4j-core@2.12.1
pax-logging-log4j2@1.11.3
2.12.3
1.11.12
1
onosproject/onos:2.2.144914a8d4b3f
log4j-core@2.13.0
pax-logging-log4j2@1.11.4
2.17.0
1.11.12
1
openzipkin/zipkin:2.21.060c3970df479
log4j-core@2.12.1
2.12.3
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
log4j-core@2.12.1
2.12.3
1
pedrocesarti/jmeter-docker:3.314851f144f57
log4j-core@2.8.2
2.12.3
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
log4j-core@2.6.2
2.12.3
1
wavefronthq/proxy:9.2d1064d28f6eb
log4j-core@2.12.1
2.12.3
1
xetusoss/archiva:v2.2.588f25242b9ee
log4j-core@2.8.2
2.12.3
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
log4j-core@2.11.1
2.12.3
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
log4j-core@2.12.1
2.12.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.