StackRadar

CVE-2022-0907

Medium

Advisory

Published 11 Mar 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
62
of 17,781 indexed, latest versions
Container images
65
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 62 of 17,781 indexed charts deploy, on 65 images.

Affected packageAffected versionsFixed inImages
tiffdeb4.0.3-7ubuntu0.9, 4.0.6-1ubuntu0.2, 4.0.6-1ubuntu0.4, 4.0.6-1ubuntu0.5+9 more4.0.3-7ubuntu0.11+esm2, 4.0.6-1ubuntu0.8+esm2, 4.0.9-5ubuntu0.6, 4.1.0+git191117-2ubuntu0.20.04.458
tiffapk4.2.0-r0, 4.2.0-r1, 4.3.0-r04.3.0-r0, 4.3.0-r17
OSV records
ALPINE-CVE-2022-0907UBUNTU-CVE-2022-0907
Also known as
USN-5523-1, USN-5523-2

Charts affected

62 by stars
ChartLatestAffected imagesRadar Score
elastictranscoderluiscajl0.46.02 of 4See more

elastictranscoder luiscajl 0.46.0

2 of the 4 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
elastictranscoder/transcoder:627e21dcb4a0327029e6
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.6
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.6

Open the chart page →

58,160
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4

Open the chart page →

22,658
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
tiff@4.0.9-5ubuntu0.3
4.0.9-5ubuntu0.6

Open the chart page →

27,633
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
tiff@4.0.9-5ubuntu0.2
4.0.9-5ubuntu0.6
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
tiff@4.0.6-1ubuntu0.5
4.0.6-1ubuntu0.8+esm2

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
tiff@4.0.6-1ubuntu0.5
4.0.6-1ubuntu0.8+esm2

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
tiff@4.0.6-1ubuntu0.5
4.0.6-1ubuntu0.8+esm2

Open the chart page →

29,124
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
tiff@4.0.3-7ubuntu0.9
4.0.3-7ubuntu0.11+esm2

Open the chart page →

26,339
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4

Open the chart page →

9,167
dolibarrraphaelVerified publisher0.0.11 of 1See more

dolibarr raphael 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
monogramm/docker-dolibarr:13.0-alpine5afd99523984
tiff@4.2.0-r0
4.3.0-r0

Open the chart page →

3,466
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.4

Open the chart page →

15,520
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
tiff@4.2.0-r1
4.3.0-r0

Open the chart page →

5,687
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-0907.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4

Open the chart page →

30,687

Container images carrying it

65 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
tiff@4.1.0+git191117-2ubuntu0.20.04.2
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
tiff@4.1.0+git191117-2ubuntu0.20.04.1
4.1.0+git191117-2ubuntu0.20.04.4
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
tiff@4.0.9-5ubuntu0.4
4.0.9-5ubuntu0.6
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
tiff@4.1.0+git191117-2ubuntu0.20.04.3
4.1.0+git191117-2ubuntu0.20.04.4
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tiff@4.0.6-1ubuntu0.6
4.0.6-1ubuntu0.8+esm2
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
tiff@4.2.0-r1
4.3.0-r0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
tiff@4.2.0-r1
4.3.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.