StackRadar

CVE-2022-24450

High

Advisory

Published 8 Feb 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
2 of 2
affected packages

Incorrect Authorization in NATS nats-server

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/nats-io/nats-server/v2golangv2.1.4, v2.1.9, v2.2.5, v2.2.6+1 more2.7.26
github.com/nats-io/nats-streaming-servergolangv0.22.00.24.11
OSV records
GHSA-g6w6-r76c-28j7
Also known as
BIT-nats-2022-24450, GO-2022-0307

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
fission-corefission-chartsVerified publisher1.14.11 of 3See more

fission-core fission-charts 1.14.1

1 of the 3 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
github.com/nats-io/nats-streaming-server@v0.22.0
0.24.1

Open the chart page →

7,104
nats-account-servernatsVerified publisher0.8.11 of 1See more

nats-account-server nats 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
github.com/nats-io/nats-server/v2@v2.3.3
2.7.2

Open the chart page →

2,634
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
natsio/nats-box:0.11.09fbf7bf684e4
github.com/nats-io/nats-server/v2@v2.1.9
2.7.2

Open the chart page →

10,629
stablecalltelemetry0.7.11 of 9See more

stable calltelemetry 0.7.1

1 of the 9 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
natsio/nats-box:0.11.09fbf7bf684e4
github.com/nats-io/nats-server/v2@v2.1.9
2.7.2

Open the chart page →

7,702
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
github.com/nats-io/nats-server/v2@v2.2.5
2.7.2

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
github.com/nats-io/nats-server/v2@v2.2.5
2.7.2

Open the chart page →

68,240
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
github.com/nats-io/nats-server/v2@v2.2.6
2.7.2

Open the chart page →

3,764
one-green-coreone-green-coreVerified publisher0.0.71 of 8See more

one-green-core one-green-core 0.0.7

1 of the 8 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
library/telegraf:1.20.428e98eece020
github.com/nats-io/nats-server/v2@v2.2.6
2.7.2

Open the chart page →

9,558
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
github.com/nats-io/nats-server/v2@v2.2.5
2.7.2

Open the chart page →

68,240
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/nats-io/nats-server/v2@v2.1.4
2.7.2

Open the chart page →

3,764
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-24450.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
github.com/nats-io/nats-server/v2@v2.3.3
2.7.2

Open the chart page →

2,634

Container images carrying it

7 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
github.com/nats-io/nats-server/v2@v2.2.5
2.7.2
3
natsio/nats-account-server:1.0.0a3381560aab6
github.com/nats-io/nats-server/v2@v2.3.3
2.7.2
2
natsio/nats-box:0.11.09fbf7bf684e4
github.com/nats-io/nats-server/v2@v2.1.9
2.7.2
2
fission/fission-bundle:1.14.13fcfd8a0fa5d
github.com/nats-io/nats-streaming-server@v0.22.0
0.24.1
1
library/telegraf:1.20.428e98eece020
github.com/nats-io/nats-server/v2@v2.2.6
2.7.2
1
library/telegraf:1.19.0-alpine794079a7f241
github.com/nats-io/nats-server/v2@v2.1.4
2.7.2
1
library/telegraf:1.19-alpineaddb86c0c520
github.com/nats-io/nats-server/v2@v2.2.6
2.7.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.