StackRadar

CVE-2022-23541

Medium

Advisory

Published 22 Dec 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.0
base score, highest
EPSS
0.008
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
84
of 17,781 indexed, latest versions
Container images
81
deployed by those charts
Fix available
1 of 1
affected package

jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC

Carried by container images the latest versions of 84 of 17,781 indexed charts deploy, on 81 images.

Affected packageAffected versionsFixed inImages
jsonwebtokennpm7.4.1, 7.4.3, 8.4.0, 8.5.19.0.081
OSV records
GHSA-hjrf-2m68-5959

Charts affected

84 by stars
ChartLatestAffected imagesRadar Score
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,436
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
jsonwebtoken@7.4.1
9.0.0

Open the chart page →

6,454
k10appk10app0.2.13 of 11See more

k10app k10app 0.2.1

3 of the 11 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
jsonwebtoken@8.5.1
9.0.0
ghcr.io/k10app/catalog:latest639c980be0f1
jsonwebtoken@8.5.1
9.0.0
ghcr.io/k10app/order:lateste1017d0dbd78
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

10,546
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,092
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

5,604
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

5,410
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

13,819
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

2,756
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

1,927
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

5,905
iotmmontesVerified publisher0.3.22 of 7See more

iot mmontes 0.3.2

2 of the 7 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
jsonwebtoken@8.5.1
9.0.0
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
jsonwebtoken@8.5.1
9.0.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

19,226
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

1,948
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

25,704
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

6,608
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_server:0.3.31a528c794270
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

109,294
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

1,866
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

9,968
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,696
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

4,285
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,881
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
jsonwebtoken@8.4.0
9.0.0

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

20,270
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

6,881
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

3,129
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-23541.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
jsonwebtoken@8.5.1
9.0.0

Open the chart page →

10,127

Container images carrying it

81 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
jsonwebtoken@8.5.1
9.0.0
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
jsonwebtoken@8.5.1
9.0.0
3
pantsel/konga:latestc8172b75607d
jsonwebtoken@8.5.1
9.0.0
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
jsonwebtoken@8.5.1
9.0.0
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
jsonwebtoken@8.5.1
9.0.0
2
governify/director:v1.4.0608c6940bb98
jsonwebtoken@8.5.1
9.0.0
2
governify/registry:v3.4.0d3f37f4f8168
jsonwebtoken@8.5.1
9.0.0
2
library/ghost:6.63.0e05bc1169fb2
jsonwebtoken@8.5.1
9.0.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
jsonwebtoken@8.5.1
9.0.0
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
jsonwebtoken@8.5.1
9.0.0
2
mojaloop/reporting:v12.1.0d480a62103d6
jsonwebtoken@8.5.1
9.0.0
2
shahanafarooqui/rtl:0.13.3e2195188a451
jsonwebtoken@8.5.1
9.0.0
2
taigaio/taiga-events:latest92fc0822564f
jsonwebtoken@8.5.1
9.0.0
2
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
jsonwebtoken@8.5.1
9.0.0
1
bicarus/http-https-echo:2785dd6a7e805e
jsonwebtoken@8.5.1
9.0.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
jsonwebtoken@8.5.1
9.0.0
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
jsonwebtoken@8.5.1
9.0.0
1
cryptexlabs/authf:0.12.11189c07411d7c
jsonwebtoken@8.5.1
9.0.0
1
denisshav/backend:latest4cc8dc5a4499
jsonwebtoken@8.5.1
9.0.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
jsonwebtoken@8.5.1
9.0.0
1
fiware/idm:8.3.3a1b6ed4ae84f
jsonwebtoken@8.5.1
9.0.0
1
getferdi/ferdi-server:1.3.26e620b85afaa
jsonwebtoken@8.5.1
9.0.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
jsonwebtoken@8.5.1
9.0.0
1
i4trust/pdc-portal:2.0.03e77858e1219
jsonwebtoken@8.5.1
9.0.0
1
jakowenko/double-take:1.6.0b858bac9e32a
jsonwebtoken@8.5.1
9.0.0
1
jayfong/yapi:1.10.2163e5d621910
jsonwebtoken@7.4.1
9.0.0
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
jsonwebtoken@8.5.1
9.0.0
1
kubevious/parser:1.0.151acf1a1f0b47
jsonwebtoken@8.5.1
9.0.0
1
kubevious/parser:1.2.299ae7a5168c2
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:6.37.01ef2e532ca4d
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:6.25.12654b1e90413
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:6.41.129773d6be407
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:4.37.0767230c0f263
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:6.39.0-alpine77196da4b0df
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:5.79.083f7bf209844
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:6.62.0a7a268bbfb7f
jsonwebtoken@8.5.1
9.0.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
jsonwebtoken@8.5.1
9.0.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
jsonwebtoken@8.5.1
9.0.0
1
louislam/uptime-kuma:1.18.5a84767d7934f
jsonwebtoken@8.5.1
9.0.0
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
jsonwebtoken@8.5.1
9.0.0
1
n8nio/n8n:0.212.0a9195bc499a3
jsonwebtoken@8.5.1
9.0.0
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
jsonwebtoken@8.5.1
9.0.0
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
jsonwebtoken@8.5.1
9.0.0
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
jsonwebtoken@8.5.1
9.0.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
jsonwebtoken@8.5.1
9.0.0
1
ondrejsika/parking:latestb1fd497416c8
jsonwebtoken@8.5.1
9.0.0
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
jsonwebtoken@8.5.1
9.0.0
1
pawelmalak/flame:2.1.193e7b0abb603
jsonwebtoken@8.5.1
9.0.0
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
jsonwebtoken@8.5.1
9.0.0
1
polonel/trudesk:1.2.60cf6513f6fe3
jsonwebtoken@8.4.0
9.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.