StackRadar

CVE-2022-1471

Critical

Advisory

Published 12 Dec 2022In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.996
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,781 indexed, latest versions
Container images
434
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: prometheus-jmx-exporter security update

Carried by container images the latest versions of 457 of 17,781 indexed charts deploy, on 434 images.

Affected packageAffected versionsFixed inImages
prometheus-jmx-exporterrpm0.12.0-6.el8, 0.12.0-7.el80:0.12.0-9.el8_710
snakeyamlmaven1.11, 1.12, 1.13, 1.15+17 more2.0434
OSV records
RHSA-2022:9058GHSA-mjmj-j48q-9wg2

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
snakeyaml@1.27
2.0

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
snakeyaml@1.26
2.0

Open the chart page →

5,806
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
prometheus-jmx-exporter@0.12.0-6.el8
snakeyaml@1.26
0:0.12.0-9.el8_7
2.0

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
snakeyaml@1.23
2.0

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
snakeyaml@1.33
2.0

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
snakeyaml@1.30
2.0

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
snakeyaml@1.33
2.0

Open the chart page →

6,016

Container images carrying it

434 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gurolakman/smsf-registration:1.0.4b22e746edd5d
snakeyaml@1.29
2.0
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
snakeyaml@1.29
2.0
1
gurolakman/ussigw-core:1.0.48739565c3ea2
snakeyaml@1.29
2.0
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
snakeyaml@1.29
2.0
1
hivemq/hivemq4:dns-4.5.144d194450d48e
snakeyaml@1.28
2.0
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
snakeyaml@1.30
2.0
1
housewrecker/gaps:latestf417dd0a7547
snakeyaml@1.29
2.0
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
snakeyaml@1.33
2.0
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
snakeyaml@1.29
2.0
1
hugohg34/planner:0.0.2171f61e8d7e2
snakeyaml@1.29
2.0
1
hugohg34/toposervice:0.0.2812a03b3f274
snakeyaml@1.29
2.0
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
snakeyaml@1.19
2.0
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
snakeyaml@1.19
2.0
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
snakeyaml@1.17
2.0
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
snakeyaml@1.15
2.0
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
snakeyaml@1.18
2.0
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
snakeyaml@1.17
2.0
1
ibmcom/microclimate-theia:lateste17bdccc5030
snakeyaml@1.17
2.0
1
j4ckhunter/consumer:1.00bb7a429e3e75
snakeyaml@1.30
2.0
1
j4ckhunter/producer:1.006ba447609b12
snakeyaml@1.30
2.0
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
snakeyaml@1.30
2.0
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
snakeyaml@1.20
2.0
1
jhidalgo3/spring-echo-example:lateste08733191ea0
snakeyaml@1.27
2.0
1
jhipster/jhipster-registry:latest7184525acd4d
snakeyaml@1.30
2.0
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
snakeyaml@1.26
2.0
1
just1not2/streama:1.10.48a2305192dec
snakeyaml@1.17
2.0
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
snakeyaml@1.32
2.0
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
snakeyaml@1.32
2.0
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
snakeyaml@1.32
2.0
1
keyfactor/signserver-ce:7.3.2798fbbe00283
snakeyaml@1.19
2.0
1
kimb88/hello-world-spring-boot:latest0639155241cb
snakeyaml@1.19
2.0
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
snakeyaml@1.27
2.0
1
kubebb/gateway-api:v5.6.04d062f20309c
snakeyaml@1.30
2.0
1
kubebb/mesh-api:v5.7.0a3879931dfa1
snakeyaml@1.33
2.0
1
ladeit/ladeit:latest962b665ffe82
snakeyaml@1.23
2.0
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
snakeyaml@1.26
2.0
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
snakeyaml@1.26
2.0
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
snakeyaml@1.27
2.0
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
snakeyaml@1.29
2.0
1
lavandadelpatio/tmdb:latestded9377636e9
snakeyaml@1.33
2.0
1
lavandadelpatio/tmdb:0.0.2f36af885e915
snakeyaml@1.27
2.0
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
snakeyaml@1.33
2.0
1
library/cassandra:4.0093ee8ee5eb2
snakeyaml@1.26
2.0
1
library/cassandra:3.11.598531a31f213
snakeyaml@1.11
2.0
1
library/cassandra:3.11.10b095ff3248c6
snakeyaml@1.11
2.0
1
library/cassandra:2.1.20cb079c0d7a57
snakeyaml@1.11
2.0
1
library/crate:4.7.0c7984a05e15b
snakeyaml@1.26
2.0
1
library/elasticsearch:7.17.0332c6d416808
snakeyaml@1.26
2.0
1
library/elasticsearch:2.4.641ed3a1a16b6
snakeyaml@1.15
2.0
1
library/elasticsearch:7.17.1588c2ec10c7f2
snakeyaml@1.33
2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.