StackRadar

CVE-2022-1471

Critical

Advisory

Published 12 Dec 2022In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.996
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
457
of 17,781 indexed, latest versions
Container images
434
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: prometheus-jmx-exporter security update

Carried by container images the latest versions of 457 of 17,781 indexed charts deploy, on 434 images.

Affected packageAffected versionsFixed inImages
prometheus-jmx-exporterrpm0.12.0-6.el8, 0.12.0-7.el80:0.12.0-9.el8_710
snakeyamlmaven1.11, 1.12, 1.13, 1.15+17 more2.0434
OSV records
RHSA-2022:9058GHSA-mjmj-j48q-9wg2

Charts affected

457 by stars
ChartLatestAffected imagesRadar Score
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
snakeyaml@1.27
2.0

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
snakeyaml@1.26
2.0

Open the chart page →

5,806
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
prometheus-jmx-exporter@0.12.0-6.el8
snakeyaml@1.26
0:0.12.0-9.el8_7
2.0

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
snakeyaml@1.23
2.0

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
snakeyaml@1.33
2.0

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
snakeyaml@1.30
2.0

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-1471.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
snakeyaml@1.33
2.0

Open the chart page →

6,016

Container images carrying it

434 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
snakeyaml@1.26
2.0
79
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
snakeyaml@1.33
2.0
13
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
snakeyaml@1.20
2.0
8
library/cassandra:3.11.3ce85468c5bad
snakeyaml@1.11
2.0
7
spdigital/prometheus-jmx-exporter-kubernetes:0.3.1e916950138ee
snakeyaml@1.16
2.0
5
gradiant/hbase-base:2.0.1a1ee6de94c04
snakeyaml@1.18
2.0
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
snakeyaml@1.26
2.0
4
mastercloudapps/planner:v1.2340a950b311b2
snakeyaml@1.29
2.0
4
oscarsotosanchez/toposervice:v1.0d4d020e9f272
snakeyaml@1.27
2.0
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
snakeyaml@1.25
2.0
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
snakeyaml@1.25
2.0
3
codeurjc/planner:v1.0800cf520c245
snakeyaml@1.29
2.0
3
mockserver/mockserver:5.15.0:mockserver-5.15.00f9ef78c9489
snakeyaml@1.33
2.0
3
pavanelthepu/todo-api:1.0.2f47658e3b24c
snakeyaml@1.28
2.0
3
selenium/hub:3.141.5902f251d48d5f
snakeyaml@1.19
2.0
3
supertokens/supertokens-postgresql:3.1418d34c781347
snakeyaml@1.24
2.0
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
snakeyaml@1.26
2.0
2
apache/druid:37.0.00116fb802786
snakeyaml@1.33
2.0
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
snakeyaml@1.19
2.0
2
dependencytrack/apiserver:4.6.3485ac0952c02
snakeyaml@1.30
2.0
2
dina1993/airports-api:latestac731244aed1
snakeyaml@1.33
2.0
2
dina1993/airports-consumer:latest669d146a5e63
snakeyaml@1.33
2.0
2
dina1993/airports-producer:latest3d6b0dac1cb4
snakeyaml@1.33
2.0
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
snakeyaml@1.17
2.0
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
snakeyaml@1.26
2.0
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
snakeyaml@1.26
2.0
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
snakeyaml@1.26
2.0
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
snakeyaml@1.26
2.0
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
snakeyaml@1.26
2.0
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
snakeyaml@1.26
2.0
2
gradiant/spark:2.4.4-python-alpine97657d56e927
snakeyaml@1.15
2.0
2
hookiesolutions/webhookie:latest0629694246ba
snakeyaml@1.29
2.0
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
snakeyaml@1.26
2.0
2
library/cassandra:3.11.65aa8400b4b3b
snakeyaml@1.11
2.0
2
library/cassandra:4.1.37cbcec0086ac
snakeyaml@1.26
2.0
2
library/elasticsearch:7.17.35e6ac15bf6a5
snakeyaml@1.26
2.0
2
library/neo4j:4.3.2-enterprise56a9453c4064
snakeyaml@1.26
2.0
2
metabase/metabase:v0.45.21fb334ce4820
snakeyaml@1.33
2.0
2
nacos/nacos-server:v2.1.0dcf04549c6d7
snakeyaml@1.23
2.0
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
snakeyaml@1.29
2.0
2
opensearchproject/opensearch:2.1.04254021a8c71
snakeyaml@1.26
2.0
2
opensearchproject/opensearch:1.1.0967d7f57f72f
snakeyaml@1.26
2.0
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
snakeyaml@1.30
2.0
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
snakeyaml@1.29
2.0
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
snakeyaml@1.29
2.0
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
snakeyaml@1.29
2.0
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
snakeyaml@1.29
2.0
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
snakeyaml@1.29
2.0
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
snakeyaml@1.29
2.0
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
snakeyaml@1.29
2.0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.