StackRadar

CVE-2022-0512

Medium

Advisory

Published 15 Feb 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
45
deployed by those charts
Fix available
1 of 1
affected package

Authorization bypass in url-parse

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 45 images.

Affected packageAffected versionsFixed inImages
url-parsenpm1.0.5, 1.2.0, 1.4.4, 1.4.7+3 more1.5.645
OSV records
GHSA-rqff-837h-mm52

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-0512.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
url-parse@1.5.3
1.5.6

Open the chart page →

3,576
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-0512.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
url-parse@1.5.4
1.5.6

Open the chart page →

3,129
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-0512.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
url-parse@1.5.1
1.5.6

Open the chart page →

2,559
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-0512.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
url-parse@1.4.7
1.5.6

Open the chart page →

5,806

Container images carrying it

45 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oscarsotosanchez/server:v1.06e2e1279126b
url-parse@1.4.7
1.5.6
4
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
url-parse@1.4.7
1.5.6
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
url-parse@1.5.1
1.5.6
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
url-parse@1.4.7
1.5.6
2
migmartri/prerender:latest486aacfd5aa9
url-parse@1.0.5
1.5.6
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
url-parse@1.5.1
1.5.6
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
url-parse@1.5.1
1.5.6
2
taigaio/taiga-events:latest92fc0822564f
url-parse@1.5.3
1.5.6
2
arfath29/3-tier-app-frontend:latest384b3e377f47
url-parse@1.5.1
1.5.6
1
arturisimo/server-urjc:v1.0d8dc4430531e
url-parse@1.4.7
1.5.6
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
url-parse@1.4.7
1.5.6
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
url-parse@1.4.7
1.5.6
1
catalysm/csmm:latestf003b35f54d9
url-parse@1.5.3
1.5.6
1
chatwoot/chatwoot:v4.15.167ebc751c171
url-parse@1.5.1
1.5.6
1
conduction/conduction-ui-app:devd591f5e6f2a9
url-parse@1.5.1
1.5.6
1
daskdev/dask-notebook:1.1.0052630f5ca04
url-parse@1.4.4
1.5.6
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
url-parse@1.4.7
1.5.6
1
fanzynoodle/smeejas:0.0.15f9916c1a287
url-parse@1.5.4
1.5.6
1
fiware/iotagent-json:3.1.0879b21a0d36d
url-parse@1.4.7
1.5.6
1
fiware/iotagent-ul:1.14.0fe11f55a926d
url-parse@1.4.7
1.5.6
1
henrywhitaker3/speedtest-tracker:latest47159a940229
url-parse@1.4.7
1.5.6
1
hugohg34/server:0.0.2503e5d8960ff
url-parse@1.4.7
1.5.6
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
url-parse@1.4.7
1.5.6
1
ibmcom/microclimate-portal:latested5505e5c7ec
url-parse@1.2.0
1.5.6
1
lissy93/dashy:2.0.51991f7be5ed0
url-parse@1.5.4
1.5.6
1
misskey/misskey:12.110.1e08b7c478093
url-parse@1.4.7
1.5.6
1
shinobisystems/shinobi:dev3ca746937856
url-parse@1.5.1
1.5.6
1
shinobisystems/shinobi:latestc2f5ce2e1067
url-parse@1.5.1
1.5.6
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
url-parse@1.5.1
1.5.6
1
slagattollas/server-practica:latest6dd8ead8e2b1
url-parse@1.4.7
1.5.6
1
socialmediamacroscope/smile_server:0.3.31a528c794270
url-parse@1.5.1
1.5.6
1
stanfordoval/almond-server:latest1a63cdccedaf
url-parse@1.5.4
1.5.6
1
taigaio/taiga-events:6.4.00bf2d24a57d9
url-parse@1.5.3
1.5.6
1
testhubio/testhub-frontend:on-preme86c2db53be8
url-parse@1.4.7
1.5.6
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
url-parse@1.5.4
1.5.6
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
url-parse@1.5.3
1.5.6
1
zazuko/trifid:2.3.7054be137de70
url-parse@1.5.1
1.5.6
1
ghcr.io/leoquote/mergeable:latest451706815103
url-parse@1.4.4
1.5.6
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
url-parse@1.5.1
1.5.6
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
url-parse@1.5.1
1.5.6
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
url-parse@1.5.1
1.5.6
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
url-parse@1.5.3
1.5.6
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
url-parse@1.0.5
1.5.6
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
url-parse@1.4.7
1.5.6
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
url-parse@1.4.7
1.5.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.