CVE-2022-24723
MediumAdvisory
Published 3 Mar 2022In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.020
- 80th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 17
- of 17,781 indexed, latest versions
- Container images
- 14
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Leading white space bypasses protocol validation
Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 14 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| urijsnpm | 1.19.1, 1.19.5, 1.19.6, 1.19.7 | 1.19.9 | 11 |
| node-uri-jsdeb | 4.2.2+dfsg-5, 4.4.0+dfsg-8 | no fix listed | 3 |
- OSV records
- GHSA-gmv4-r438-p67fUBUNTU-CVE-2022-24723
Charts affected
17 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| codehubcodehubVerified publisher | 6.2.18 | 1 of 5See more | 13,220 |
| amundsenduyet | 1.1.0 | 1 of 7See more | 11,174 |
| tampkubebb | 5.6.0 | 1 of 2See more | 4,664 |
| tapm-componentkubebb | 5.7.1 | 1 of 3See more | 10,264 |
| tdsfkubebb | 5.7.0 | 1 of 3See more | 6,490 |
| nublado2lsst-sqre | 0.8.5 | 1 of 2See more | 17,779 |
| account-lookup-servicemojaloop | 13.0.0 | 1 of 4See more | 11,695 |
| account-lookup-service-adminmojaloop | 13.0.0 | 1 of 4See more | 11,695 |
| admin-api-svcmojaloop | 12.0.0 | 1 of 4See more | 12,108 |
| fspiop-transfer-api-svcmojaloop | 12.0.1 | 1 of 3See more | 11,479 |
| mojaloopmojaloop | 14.0.0 | 3 of 6See more | 19,226 |
| flomesh-consoleopenshift | 0.70.0-30-ubi8 | 1 of 2See more | 9,968 |
| nordmart-reviewstakaterVerified publisher | 0.0.6 | 1 of 3See more | 11,554 |
| nordmart-review-instancestakaterVerified publisher | 1.0.0 | 1 of 3See more | 11,554 |
| grafanasvtech-public-helm-charts | 1.0.0 | 1 of 2See more | 10,902 |
| cadencewenerme | 0.23.0 | 1 of 5See more | 10,127 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
Container images carrying it
14 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| mojaloop/ | b06d3287ea82 | urijs | 1.19.9 | 3 |
| mojaloop/ | 1abc8a7aa71c | urijs | 1.19.9 | 2 |
| mojaloop/ | fb71d233c742 | urijs | 1.19.9 | 2 |
| stakater/ | 3f4926eedc74 | urijs | 1.19.9 | 2 |
| amundsendev/ | 69e7915e61c1 | urijs | 1.19.9 | 1 |
| jupyterhub/ | 3974ba945e65 | node-uri-js | no fix listed | 1 |
| kubebb/ | fadac6d52470 | urijs | 1.19.9 | 1 |
| kubebb/ | 258458311bc9 | urijs | 1.19.9 | 1 |
| lsstsqre/ | b75bf8aaafa4 | node-uri-js | no fix listed | 1 |
| refar/ | dcca8e4477a6 | urijs | 1.19.9 | 1 |
| svtechnmaa/ | 1d71314424aa | node-uri-js | no fix listed | 1 |
| temporalio/ | 33cfa863d8ce | urijs | 1.19.9 | 1 |
| ubercadence/ | 8564a5b44a6d | urijs | 1.19.9 | 1 |
| quay.io/ | ce6938ff6709 | urijs | 1.19.9 | 1 |