StackRadar

CVE-2022-0624

High

Advisory

Published 29 Jun 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Authorization Bypass in parse-path

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
parse-pathnpm4.0.1, 4.0.3, 4.0.45.0.010
OSV records
GHSA-3j8f-xvm3-ffx4

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
parse-path@4.0.1
5.0.0

Open the chart page →

8,213
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
parse-path@4.0.3
5.0.0

Open the chart page →

7,579
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
parse-path@4.0.3
5.0.0

Open the chart page →

3,476
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
parse-path@4.0.1
5.0.0

Open the chart page →

17,896
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
ghcr.io/data-fair/metrics:0a8d40779eeae
parse-path@4.0.3
5.0.0
ghcr.io/data-fair/simple-directory:438a4f32fad82
parse-path@4.0.3
5.0.0

Open the chart page →

38,346
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
parse-path@4.0.1
5.0.0

Open the chart page →

25,456
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
parse-path@4.0.1
5.0.0

Open the chart page →

8,213
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
parse-path@4.0.4
5.0.0

Open the chart page →

4,944
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
parse-path@4.0.1
5.0.0

Open the chart page →

7,232
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-0624.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
parse-path@4.0.3
5.0.0

Open the chart page →

9,968

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
parse-path@4.0.1
5.0.0
2
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
parse-path@4.0.1
5.0.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
parse-path@4.0.4
5.0.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
parse-path@4.0.3
5.0.0
1
roadiehq/community-backstage-image:latestef355bf5b639
parse-path@4.0.1
5.0.0
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
parse-path@4.0.3
5.0.0
1
ghcr.io/data-fair/metrics:0a8d40779eeae
parse-path@4.0.3
5.0.0
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
parse-path@4.0.3
5.0.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
parse-path@4.0.3
5.0.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
parse-path@4.0.1
5.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.