StackRadar

CVE-2024-21742

Medium

Advisory

Published 27 Feb 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
24
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

Apache James MIME4J improper input validation vulnerability

Carried by container images the latest versions of 24 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
apache-mime4j-coremaven0.7.2, 0.8.1, 0.8.3, 0.8.4+2 more0.8.1021
OSV records
GHSA-jw7r-rxff-gv24

Charts affected

24 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
apache-mime4j-core@0.8.4
0.8.10

Open the chart page →

7,713
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

6,048
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
apache-mime4j-core@0.8.9
0.8.10

Open the chart page →

27,267
musicocielmusicocielVerified publisher0.0.01 of 3See more

musicociel musicociel 0.0.0

1 of the 3 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
apache-mime4j-core@0.8.9
0.8.10

Open the chart page →

4,406
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
apache-mime4j-core@0.8.9
0.8.10

Open the chart page →

19,691
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
apache-mime4j-core@0.8.4
0.8.10

Open the chart page →

38,346
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

6,110
clowder2ncsaVerified publisher1.9.72 of 12See more

clowder2 ncsa 1.9.7

2 of the 12 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
apache-mime4j-core@0.8.9
0.8.10
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

37,373
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

24,930
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
apache-mime4j-core@0.8.4
0.8.10

Open the chart page →

7,713
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
apache-mime4j-core@0.8.9
0.8.10

Open the chart page →

16,975
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
apache-mime4j-core@0.8.7
0.8.10

Open the chart page →

13,352
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

9,722
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

6,915
gerrit-operatorepmdedpVerified publisher2.25.01 of 2See more

gerrit-operator epmdedp 2.25.0

1 of the 2 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
epamedp/edp-gerrit:3.14.249e8fe9c4855
apache-mime4j-core@0.8.1
0.8.10

Open the chart page →

1,159
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
apache-mime4j-core@0.8.4
0.8.10

Open the chart page →

9,920
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
apache-mime4j-core@0.8.9
0.8.10

Open the chart page →

3,683
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
apache-mime4j-core@0.7.2
0.8.10

Open the chart page →

63,223
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

6,443
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

8,806
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

12,455
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-21742.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
apache-mime4j-core@0.8.3
0.8.10

Open the chart page →

6,016

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
apache-mime4j-core@0.8.3
0.8.10
3
quay.io/keycloak/keycloak:20.0054ef67eb7da
apache-mime4j-core@0.8.3
0.8.10
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
apache-mime4j-core@0.8.4
0.8.10
2
apache/tika:2.9.0.092d055a84e9e
apache-mime4j-core@0.8.9
0.8.10
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
apache-mime4j-core@0.8.3
0.8.10
1
assistiot/identity-manager_kc:latest0df4b4fa899a
apache-mime4j-core@0.8.7
0.8.10
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
apache-mime4j-core@0.8.9
0.8.10
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
apache-mime4j-core@0.8.9
0.8.10
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
apache-mime4j-core@0.8.3
0.8.10
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
apache-mime4j-core@0.8.4
0.8.10
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
apache-mime4j-core@0.8.1
0.8.10
1
library/solr:8.7.0d124efd81fbb
apache-mime4j-core@0.8.3
0.8.10
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
apache-mime4j-core@0.8.9
0.8.10
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
apache-mime4j-core@0.7.2
0.8.10
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
apache-mime4j-core@0.8.3
0.8.10
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
apache-mime4j-core@0.8.3
0.8.10
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
apache-mime4j-core@0.8.9
0.8.10
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
apache-mime4j-core@0.8.4
0.8.10
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
apache-mime4j-core@0.8.9
0.8.10
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
apache-mime4j-core@0.8.3
0.8.10
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
apache-mime4j-core@0.8.3
0.8.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.