StackRadar

CVE-2022-24772

High

Advisory

Published 18 Mar 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
51
deployed by those charts
Fix available
1 of 1
affected package

Improper Verification of Cryptographic Signature in node-forge

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
node-forgenpm0.7.1, 0.7.6, 0.8.0, 0.8.5+4 more1.3.051
OSV records
GHSA-x4jg-mjrx-434g

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-24772.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
node-forge@0.10.0
1.3.0

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24772.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
node-forge@0.10.0
1.3.0

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-24772.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
node-forge@0.10.0
1.3.0

Open the chart page →

3,881
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-24772.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
node-forge@0.10.0
1.3.0

Open the chart page →

20,270
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2022-24772.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
node-forge@0.10.0
1.3.0

Open the chart page →

2,838
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-24772.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
node-forge@0.10.0
1.3.0

Open the chart page →

5,806

Container images carrying it

51 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/wekan/wekan:v5.65cb17600883a3
node-forge@0.7.1
1.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.