StackRadar

CVE-2022-23539

High

Advisory

Published 22 Dec 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
84
of 17,781 indexed, latest versions
Container images
81
deployed by those charts
Fix available
1 of 1
affected package

jsonwebtoken unrestricted key type could lead to legacy keys usage

Carried by container images the latest versions of 84 of 17,781 indexed charts deploy, on 81 images.

Affected packageAffected versionsFixed inImages
jsonwebtokennpm7.4.1, 7.4.3, 8.4.0, 8.5.19.0.081
OSV records
GHSA-8cf7-32gw-wr33

Charts affected

84 by stars
ChartLatestAffected imagesRadar Score
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,436
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
jsonwebtoken@7.4.1
9.0.0

Open the chart page →

6,454
k10appk10app0.2.13 of 11See more

k10app k10app 0.2.1

3 of the 11 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
jsonwebtoken@8.5.1
9.0.0
ghcr.io/k10app/catalog:latest639c980be0f1
jsonwebtoken@8.5.1
9.0.0
ghcr.io/k10app/order:lateste1017d0dbd78
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

10,546
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,092
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

5,604
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

5,410
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

13,819
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

2,756
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

1,927
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

5,905
iotmmontesVerified publisher0.3.22 of 7See more

iot mmontes 0.3.2

2 of the 7 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
jsonwebtoken@8.5.1
9.0.0
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

19,226
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

1,948
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

25,704
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

6,608
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_server:0.3.31a528c794270
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

109,294
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

1,866
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

9,968
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,696
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

4,285
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,881
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
jsonwebtoken@8.4.0
9.0.0

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

20,270
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

6,881
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,129
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-23539.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

10,127

Container images carrying it

81 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
requarks/wiki:canary-2.5.2438b5865a7386c
jsonwebtoken@8.5.1
9.0.0
1
roadiehq/community-backstage-image:latestef355bf5b639
jsonwebtoken@8.5.1
9.0.0
1
samajh/alprbackend:latestea742b4372ad
jsonwebtoken@8.5.1
9.0.0
1
shahanafarooqui/rtl:0.11.0d0cd3d868aca
jsonwebtoken@8.5.1
9.0.0
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
jsonwebtoken@8.5.1
9.0.0
1
socialmediamacroscope/smile_server:0.3.31a528c794270
jsonwebtoken@8.5.1
9.0.0
1
sqlpad/sqlpad:6.7d3d2f430dffd
jsonwebtoken@8.5.1
9.0.0
1
stanfordoval/almond-server:latest1a63cdccedaf
jsonwebtoken@8.5.1
9.0.0
1
taigaio/taiga-events:6.4.00bf2d24a57d9
jsonwebtoken@8.5.1
9.0.0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
jsonwebtoken@8.5.1
9.0.0
1
tzahi12345/youtubedl-material:4.23720b856bd2f
jsonwebtoken@8.5.1
9.0.0
1
ubercadence/web:v3.29.58564a5b44a6d
jsonwebtoken@8.5.1
9.0.0
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
jsonwebtoken@8.5.1
9.0.0
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
jsonwebtoken@7.4.1
9.0.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
jsonwebtoken@7.4.3
9.0.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
jsonwebtoken@7.4.3
9.0.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
jsonwebtoken@7.4.3
9.0.0
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/k10app/catalog:latest639c980be0f1
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/k10app/order:lateste1017d0dbd78
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/leoquote/mergeable:latest451706815103
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
jsonwebtoken@8.5.1
9.0.0
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
jsonwebtoken@8.5.1
9.0.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
jsonwebtoken@8.5.1
9.0.0
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
jsonwebtoken@8.5.1
9.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.