StackRadar

CVE-2022-23491

High

Advisory

Published 5 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
679
of 17,787 indexed, latest versions
Container images
631
deployed by those charts
Fix available
2 of 3
affected packages

Certifi removing TrustCor root certificate

Carried by container images the latest versions of 679 of 17,787 indexed charts deploy, on 631 images.

Affected packageAffected versionsFixed inImages
ca-certificatesdeb20130906ubuntu2, 20141019ubuntu0.14.04.1, 20160104ubuntu1, 20170717~14.04.1+18 more20211016~14.04.1~esm1, 20211016~16.04.1~esm2, 20211016ubuntu0.18.04.1, 20211016ubuntu0.20.04.1+1 more345
python-certifideb2022.9.24-1no fix listed15
certifipypi2017.11.05, 2017.11.5, 2018.1.18, 2018.4.16+19 more2022.12.07350
OSV records
DEBIAN-CVE-2022-23491UBUNTU-CVE-2022-23491GHSA-43fp-rhv2-5gv8
Also known as
PYSEC-2022-42986, USN-5761-1, USN-5761-2

Charts affected

679 by stars
ChartLatestAffected imagesRadar Score
pagestest43221.0.02 of 3See more

pages test4322 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
flyway/flyway:6.4.422d97ceb0c47
ca-certificates@20180409
20211016ubuntu0.18.04.1

Open the chart page →

20,190
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
certifi@2021.10.8
2022.12.07

Open the chart page →

5,321
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
certifi@2020.6.20
2022.12.07

Open the chart page →

2,408
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
ca-certificates@20160104ubuntu1
20211016~16.04.1~esm2

Open the chart page →

11,007
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
flyway/flyway:6.4.422d97ceb0c47
ca-certificates@20180409
20211016ubuntu0.18.04.1

Open the chart page →

20,190
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
certifi@2021.10.8
2022.12.07

Open the chart page →

18,908
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
flyway/flyway:6.4.422d97ceb0c47
ca-certificates@20180409
20211016ubuntu0.18.04.1

Open the chart page →

20,190
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
certifi@2020.6.20
2022.12.07

Open the chart page →

4,423
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
certifi@2022.6.15.1
2022.12.07

Open the chart page →

8,607
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
ca-certificates@20170717~16.04.2
20211016~16.04.1~esm2

Open the chart page →

15,330
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
certifi@2020.6.20
2022.12.07

Open the chart page →

13,459
pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
flyway/flyway:6.4.422d97ceb0c47
ca-certificates@20180409
20211016ubuntu0.18.04.1

Open the chart page →

20,190
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
ca-certificates@20210119~18.04.1
20211016ubuntu0.18.04.1

Open the chart page →

7,885
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
certifi@2018.8.24
2022.12.07

Open the chart page →

11,405
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
flyway/flyway:6.4.422d97ceb0c47
ca-certificates@20180409
20211016ubuntu0.18.04.1

Open the chart page →

20,190
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
ca-certificates@20210119~20.04.2
certifi@2020.4.5.1
20211016ubuntu0.20.04.1
2022.12.07

Open the chart page →

11,119
wbaas-backupwbstack0.1.01 of 1See more

wbaas-backup wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
ca-certificates@20210119~18.04.2
20211016ubuntu0.18.04.1

Open the chart page →

9,743
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
certifi@2021.10.8
2022.12.07

Open the chart page →

2,670
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
ca-certificates@20210119~20.04.2
20211016ubuntu0.20.04.1

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
ca-certificates@20210119~20.04.2
20211016ubuntu0.20.04.1

Open the chart page →

28,605
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
certifi@2020.6.20
2022.12.07

Open the chart page →

4,086
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
ca-certificates@20190110~18.04.1
20211016ubuntu0.18.04.1

Open the chart page →

10,843
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
python-certifi@2022.9.24-1
certifi@2022.9.24
no fix listed
2022.12.07

Open the chart page →

9,117
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
ca-certificates@20210119~20.04.2
20211016ubuntu0.20.04.1

Open the chart page →

15,230
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2022.12.07

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
certifi@2018.10.15
2022.12.07

Open the chart page →

11,784
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
certifi@2020.12.5
2022.12.07

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
certifi@2021.10.8
2022.12.07

Open the chart page →

2,643
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2022-23491.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
ca-certificates@20210119~18.04.2
20211016ubuntu0.18.04.1
yandex/clickhouse-server:21.3.204eccfffb01d7
ca-certificates@20210119~20.04.2
20211016ubuntu0.20.04.1

Open the chart page →

9,207

Container images carrying it

631 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
certifi@2020.12.5
2022.12.07
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
certifi@2020.12.5
2022.12.07
1
countly/countly-server:25.05.4e3c238248f99
certifi@2019.11.28
2022.12.07
1
craigwillis/c2metadata-bd:latestae317d7e4724
certifi@2020.11.8
2022.12.07
1
cribl/cribl:3.0.2762747cb6796
ca-certificates@20210119~18.04.1
20211016ubuntu0.18.04.1
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
ca-certificates@20210119~16.04.1
20211016~16.04.1~esm2
1
danuk/telegram-sender:0.0.1026560388070
certifi@2022.9.24
2022.12.07
1
daskdev/dask:1.1.04ecd7bc35500
certifi@2018.11.29
2022.12.07
1
daskdev/dask-notebook:1.1.0052630f5ca04
ca-certificates@20180409
certifi@2018.11.29
20211016ubuntu0.18.04.1
2022.12.07
1
datadog/agent:7.22.08f20e56b5311
certifi@2020.6.20
2022.12.07
1
datadog/agent:6aad9994de6a7
certifi@2021.10.8
2022.12.07
1
datalust/seq:5.0.832-pre9c731bb207a6
ca-certificates@20170717~16.04.1
20211016~16.04.1~esm2
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
ca-certificates@20211016~20.04.1
20211016ubuntu0.20.04.1
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
certifi@2020.6.20
2022.12.07
1
datawire/aes:1.13.62beb65062c8b
certifi@2020.6.20
2022.12.07
1
datawire/emissary:2.0.2-ea9716efbdd24b
certifi@2020.6.20
2022.12.07
1
dchesterton/amcrest2mqtt:1.0.9cc70f2238aa9
certifi@2021.5.30
2022.12.07
1
deconzcommunity/deconz:2.29.2062de2362641
python-certifi@2022.9.24-1
certifi@2022.9.24
no fix listed
2022.12.07
1
deconzcommunity/deconz:2.12.066541bbb78952
certifi@2018.8.24
2022.12.07
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
ca-certificates@20211016~20.04.1
20211016ubuntu0.20.04.1
1
deepflowce/deepflow-app:v6.2.6.5a1888d35e787
certifi@2021.10.8
2022.12.07
1
deepflowce/mysql:8.0.313d7ae561cf60
certifi@2022.6.15
2022.12.07
1
dellcloud/category:distributed02fc234353a9
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
1
dellcloud/pages:1.04d2eb25b9225
ca-certificates@20201027ubuntu0.20.04.1
20211016ubuntu0.20.04.1
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
certifi@2021.10.8
2022.12.07
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
ca-certificates@20211016~20.04.1
20211016ubuntu0.20.04.1
1
dniel/api-posts:master45a667852f2a
ca-certificates@20180409
20211016ubuntu0.18.04.1
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
certifi@2021.10.8
2022.12.07
1
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
certifi@2021.10.8
2022.12.07
1
douz/helpdesk:latest4384103d0219
certifi@2022.6.15
2022.12.07
1
dysnix/pritunl:v1.29-r819951e3e7a32
certifi@2020.4.5.1
2022.12.07
1
elastic/apm-server:7.17.6c7a1c63257d0
ca-certificates@20211016~20.04.1
20211016ubuntu0.20.04.1
1
elastichq/elasticsearch-hq:latestbb3bd22c2b87
certifi@2019.9.11
2022.12.07
1
elastictranscoder/media:627e21dc963ab3858c6b
ca-certificates@20190110~18.04.1
20211016ubuntu0.18.04.1
1
elastictranscoder/media-storage:f6d861a026208b8c2359
ca-certificates@20190110~18.04.1
20211016ubuntu0.18.04.1
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
ca-certificates@20190110~18.04.1
20211016ubuntu0.18.04.1
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
ca-certificates@20190110~18.04.1
20211016ubuntu0.18.04.1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
ca-certificates@20210119~20.04.2
20211016ubuntu0.20.04.1
1
engrmth/bnkr:2.1.06d8464e6f0e8
ca-certificates@20210119~20.04.2
20211016ubuntu0.20.04.1
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
ca-certificates@20210119~18.04.1
20211016ubuntu0.18.04.1
1
erlangsolutions/wombatoam:4.1.284680c990147a
certifi@2020.6.20
2022.12.07
1
errbotio/errbot:6.1.900ee4e0953ab
certifi@2022.5.18.1
2022.12.07
1
esphome/esphome:1.18.03f51ec10e823
certifi@2020.12.5
2022.12.07
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ca-certificates@20170717~16.04.1
20211016~16.04.1~esm2
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
certifi@2022.9.24
2022.12.07
1
fiware/bae-activation-service:v0.0.33e3ec88d59ed
certifi@2020.12.5
2022.12.07
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
certifi@2019.11.28
2022.12.07
1
flag5/clustersecret:0.0.94ad5748bfcc6
certifi@2021.10.8
2022.12.07
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
certifi@2020.11.8
2022.12.07
1
foldingathome/fah-gpu:latest5ef7742d1eb4
ca-certificates@20210119~18.04.1
20211016ubuntu0.18.04.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.