StackRadar

CVE-2024-21501

Medium

Advisory

Published 24 Feb 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

sanitize-html Information Exposure vulnerability

Carried by container images the latest versions of 26 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
sanitize-htmlnpm1.14.1, 1.18.5, 1.19.1, 1.27.5+4 more2.12.121
OSV records
GHSA-rm97-x556-q36h

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
sanitize-html@1.14.1
2.12.1

Open the chart page →

10,732
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
sanitize-html@2.7.0
2.12.1

Open the chart page →

5,251
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
sanitize-html@2.7.0
2.12.1

Open the chart page →

7,776
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
sanitize-html@2.11.0
2.12.1
ghcr.io/data-fair/portals:18b621866ceb2
sanitize-html@1.27.5
2.12.1

Open the chart page →

38,346
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
sanitize-html@2.7.0
2.12.1

Open the chart page →

4,260
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
sanitize-html@1.18.5
2.12.1

Open the chart page →

29,901
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
sanitize-html@2.11.0
2.12.1

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
sanitize-html@2.11.0
2.12.1

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
sanitize-html@2.11.0
2.12.1

Open the chart page →

5,141
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
sanitize-html@1.19.1
2.12.1

Open the chart page →

11,174
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
sanitize-html@2.11.0
2.12.1

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sanitize-html@1.27.5
2.12.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sanitize-html@1.27.5
2.12.1

Open the chart page →

24,319
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
sanitize-html@2.7.0
2.12.1

Open the chart page →

5,410
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sanitize-html@1.27.5
2.12.1

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sanitize-html@1.27.5
2.12.1

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sanitize-html@1.27.5
2.12.1

Open the chart page →

12,108
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sanitize-html@1.27.5
2.12.1
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sanitize-html@1.27.5
2.12.1
mojaloop/role-assignment-service:v2.1.0def4bf273721
sanitize-html@1.27.5
2.12.1

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sanitize-html@1.27.5
2.12.1

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sanitize-html@1.27.5
2.12.1
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sanitize-html@1.27.5
2.12.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sanitize-html@1.27.5
2.12.1

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sanitize-html@1.27.5
2.12.1

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sanitize-html@1.27.5
2.12.1

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
sanitize-html@1.27.5
2.12.1

Open the chart page →

2,316
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sanitize-html@2.3.3
2.12.1

Open the chart page →

9,968
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
sanitize-html@2.8.1
2.12.1

Open the chart page →

14,679
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-21501.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
sanitize-html@2.7.0
2.12.1

Open the chart page →

4,017

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sanitize-html@1.27.5
2.12.1
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
sanitize-html@2.11.0
2.12.1
3
governify/assets-manager:v1.4.12987672448c7
sanitize-html@1.27.5
2.12.1
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sanitize-html@1.27.5
2.12.1
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sanitize-html@1.27.5
2.12.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sanitize-html@1.27.5
2.12.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sanitize-html@1.27.5
2.12.1
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
sanitize-html@1.27.5
2.12.1
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
sanitize-html@1.19.1
2.12.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
sanitize-html@1.18.5
2.12.1
1
library/ghost:4.37.0767230c0f263
sanitize-html@2.7.0
2.12.1
1
library/ghost:5.79.083f7bf209844
sanitize-html@2.11.0
2.12.1
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
sanitize-html@1.14.1
2.12.1
1
misskey/misskey:12.110.1e08b7c478093
sanitize-html@2.7.0
2.12.1
1
n8nio/n8n:0.212.0a9195bc499a3
sanitize-html@2.7.0
2.12.1
1
polonel/trudesk:1.2.60cf6513f6fe3
sanitize-html@2.7.0
2.12.1
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
sanitize-html@2.8.1
2.12.1
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
sanitize-html@2.7.0
2.12.1
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
sanitize-html@2.11.0
2.12.1
1
ghcr.io/data-fair/portals:18b621866ceb2
sanitize-html@1.27.5
2.12.1
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sanitize-html@2.3.3
2.12.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.