StackRadar

CVE-2022-24723

Medium

Advisory

Published 3 Mar 2022In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 2
affected packages

Leading white space bypasses protocol validation

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
urijsnpm1.19.1, 1.19.5, 1.19.6, 1.19.71.19.911
node-uri-jsdeb4.2.2+dfsg-5, 4.4.0+dfsg-8no fix listed3
OSV records
GHSA-gmv4-r438-p67fUBUNTU-CVE-2022-24723

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-uri-js@4.4.0+dfsg-8
no fix listed

Open the chart page →

13,220
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
urijs@1.19.1
1.19.9

Open the chart page →

11,174
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
kubebb/tamp-portal:v5.6.0fadac6d52470
urijs@1.19.6
1.19.9

Open the chart page →

4,664
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
refar/apm-portal:v5.7.1dcca8e4477a6
urijs@1.19.6
1.19.9

Open the chart page →

10,264
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
kubebb/tdsf-portal:v5.7.0258458311bc9
urijs@1.19.7
1.19.9

Open the chart page →

6,490
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-uri-js@4.2.2+dfsg-5
no fix listed

Open the chart page →

17,779
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
urijs@1.19.7
1.19.9

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
urijs@1.19.7
1.19.9

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
urijs@1.19.7
1.19.9

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
urijs@1.19.6
1.19.9

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
urijs@1.19.7
1.19.9
mojaloop/central-ledger:v13.14.01abc8a7aa71c
urijs@1.19.7
1.19.9
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
urijs@1.19.6
1.19.9

Open the chart page →

19,226
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
urijs@1.19.7
1.19.9

Open the chart page →

9,968
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
urijs@1.19.6
1.19.9

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
urijs@1.19.6
1.19.9

Open the chart page →

11,554
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-uri-js@4.2.2+dfsg-5
no fix listed

Open the chart page →

10,902
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
urijs@1.19.5
1.19.9

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-24723.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
urijs@1.19.7
1.19.9

Open the chart page →

22,665

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
urijs@1.19.7
1.19.9
3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
urijs@1.19.7
1.19.9
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
urijs@1.19.6
1.19.9
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
urijs@1.19.6
1.19.9
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
urijs@1.19.1
1.19.9
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-uri-js@4.4.0+dfsg-8
no fix listed
1
kubebb/tamp-portal:v5.6.0fadac6d52470
urijs@1.19.6
1.19.9
1
kubebb/tdsf-portal:v5.7.0258458311bc9
urijs@1.19.7
1.19.9
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-uri-js@4.2.2+dfsg-5
no fix listed
1
refar/apm-portal:v5.7.1dcca8e4477a6
urijs@1.19.6
1.19.9
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-uri-js@4.2.2+dfsg-5
no fix listed
1
temporalio/web:1.14.033cfa863d8ce
urijs@1.19.7
1.19.9
1
ubercadence/web:v3.29.58564a5b44a6d
urijs@1.19.5
1.19.9
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
urijs@1.19.7
1.19.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.