StackRadar

CVE-2022-1650

Critical

Advisory

Published 13 May 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.3
base score, highest
EPSS
0.019
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
25
of 17,781 indexed, latest versions
Container images
23
deployed by those charts
Fix available
1 of 1
affected package

Exposure of Sensitive Information in eventsource

Carried by container images the latest versions of 25 of 17,781 indexed charts deploy, on 23 images.

Affected packageAffected versionsFixed inImages
eventsourcenpm0.1.6, 1.0.7, 1.1.01.1.123
OSV records
GHSA-6h5x-7c5m-7cr7

Charts affected

25 by stars
ChartLatestAffected imagesRadar Score
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
eventsource@1.1.0
1.1.1

Open the chart page →

9,203
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
eventsource@1.0.7
1.1.1

Open the chart page →

5,251
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
eventsource@1.1.0
1.1.1

Open the chart page →

5,946
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
eventsource@1.1.0
1.1.1

Open the chart page →

7,801
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
eventsource@1.1.0
1.1.1

Open the chart page →

5,940
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
eventsource@1.0.7
1.1.1

Open the chart page →

7,517
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
eventsource@1.1.0
1.1.1

Open the chart page →

3,237
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
eventsource@1.0.7
1.1.1

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
eventsource@1.0.7
1.1.1

Open the chart page →

12,907
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
eventsource@1.0.7
1.1.1

Open the chart page →

4,223
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
eventsource@1.1.0
1.1.1

Open the chart page →

3,744
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
eventsource@1.1.0
1.1.1

Open the chart page →

4,127
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
eventsource@0.1.6
1.1.1

Open the chart page →

4,614
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
eventsource@1.1.0
1.1.1

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
eventsource@1.1.0
1.1.1

Open the chart page →

5,940
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
eventsource@1.0.7
1.1.1

Open the chart page →

6,438
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
eventsource@0.1.6
1.1.1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
eventsource@0.1.6
1.1.1

Open the chart page →

7,048
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
eventsource@1.1.0
1.1.1

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
eventsource@0.1.6
1.1.1

Open the chart page →

109,294
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
eventsource@1.1.0
1.1.1

Open the chart page →

9,968
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
eventsource@1.0.7
1.1.1

Open the chart page →

2,460
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
eventsource@1.1.0
1.1.1

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
eventsource@1.1.0
1.1.1

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
eventsource@0.1.6
1.1.1

Open the chart page →

3,881
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-1650.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
eventsource@1.1.0
1.1.1

Open the chart page →

3,576

Container images carrying it

23 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chatwoot/chatwoot:v3.1.0d530ab8c1753
eventsource@1.1.0
1.1.1
2
migmartri/prerender:latest486aacfd5aa9
eventsource@0.1.6
1.1.1
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
eventsource@1.1.0
1.1.1
2
arfath29/3-tier-app-frontend:latest384b3e377f47
eventsource@1.1.0
1.1.1
1
catalysm/csmm:latestf003b35f54d9
eventsource@1.1.0
1.1.1
1
chatwoot/chatwoot:v4.15.167ebc751c171
eventsource@1.1.0
1.1.1
1
conduction/conduction-ui-app:devd591f5e6f2a9
eventsource@1.0.7
1.1.1
1
fanzynoodle/smeejas:0.0.15f9916c1a287
eventsource@1.1.0
1.1.1
1
henrywhitaker3/speedtest-tracker:latest47159a940229
eventsource@1.0.7
1.1.1
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
eventsource@1.1.0
1.1.1
1
lissy93/dashy:2.0.51991f7be5ed0
eventsource@1.1.0
1.1.1
1
misskey/misskey:12.110.1e08b7c478093
eventsource@1.0.7
1.1.1
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
eventsource@0.1.6
1.1.1
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
eventsource@0.1.6
1.1.1
1
testhubio/testhub-frontend:on-preme86c2db53be8
eventsource@1.0.7
1.1.1
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
eventsource@1.1.0
1.1.1
1
ghcr.io/leoquote/mergeable:latest451706815103
eventsource@1.0.7
1.1.1
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
eventsource@1.1.0
1.1.1
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
eventsource@1.1.0
1.1.1
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
eventsource@1.1.0
1.1.1
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
eventsource@0.1.6
1.1.1
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
eventsource@1.0.7
1.1.1
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
eventsource@1.0.7
1.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.