StackRadar

CVE-2022-21235

Critical

Advisory

Published 1 Apr 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 1
affected package

Command Injection Vulnerability with Mercurial in VCS

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
github.com/Masterminds/vcsgolangv1.13.0, v1.13.11.13.258
OSV records
GHSA-6635-c626-vj4r
Also known as
GO-2022-0414, SNYK-GOLANG-GITHUBCOMMASTERMINDSVCS-2437078

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

10,466
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

30,687
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

28,165
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,480
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,510
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,429
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-21235.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/Masterminds/vcs@v1.13.1
1.13.2

Open the chart page →

7,552

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/Masterminds/vcs@v1.13.1
1.13.2
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/Masterminds/vcs@v1.13.1
1.13.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.