CVE-2022-23959
UnscoredAdvisory
Published 14 Feb 2022In the index since 8 Sept 2026
- Severity
- Unscored
- worst across findings
- CVSS
- —
- base score, highest
- EPSS
- 0.020
- 79th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 8
- deployed by those charts
- Fix available
- 1 of 1
- affected package
varnish - security update
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 8 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| varnishdeb | 5.0.0-7+deb9u2 | 5.0.0-7+deb9u3 | 8 |
- OSV records
- DLA-2920-1
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| balance-registrationbalance-registration | 0.1.0 | 1 of 4See more | 8,408 |
| checkin-componentcheckin-component | 0.1.0 | 1 of 4See more | 8,408 |
| cgrccommongroundregistratiecomponent | 0.1.0 | 1 of 3See more | 7,572 |
| conduction-uiconduction-ui | 0.1.0 | 1 of 6See more | 12,907 |
| contactmoment-componentcontactmoment-component | 0.1.0 | 1 of 4See more | 8,408 |
| docparserdocparser | 0.1.0 | 1 of 4See more | 8,408 |
| kvkkvkservice | 0.1.0 | 1 of 4See more | 8,534 |
| panproto-application-nldesign | 0.1.0 | 1 of 5See more | 8,725 |
Container images carrying it
8 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| conduction/ | 07c44005da9d | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | e154d5781c8a | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | ef3a3fb0ad47 | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | 5f5add2c12e0 | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | e3546b97faea | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | 45f20c4cd2fa | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | 8722700f1768 | varnish | 5.0.0-7+deb9u3 | 1 |
| conduction/ | c3e5737ae68f | varnish | 5.0.0-7+deb9u3 | 1 |