CVE-2022-24775
MediumAdvisory
Published 21 Mar 2022In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.025
- 84th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 72
- of 17,781 indexed, latest versions
- Container images
- 63
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Improper Input Validation in guzzlehttp/psr7
Carried by container images the latest versions of 72 of 17,781 indexed charts deploy, on 63 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| guzzlehttp/ | 1.4.2, 1.5.2, 1.6.1, 1.7.0+4 more | 1.8.4, 2.1.1 | 63 |
| drupal/ | 8.9.20 | 9.2.16 | 1 |
- OSV records
- GHSA-q7rv-6hp3-vh96DRUPAL-CORE-2022-006
- Also known as
- BIT-drupal-2022-24775
Charts affected
72 by stars
Container images carrying it
63 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| cachethq/ | a61ff0f67ea7 | guzzlehttp/ | 1.8.4 | 4 |
| buddy/ | 097c897f8b54 | guzzlehttp/ | 1.8.4 | 3 |
| mautic/ | a954c5868d76 | guzzlehttp/ | 1.8.4 | 3 |
| ldapaccountmanager/ | d46cf25d1dda | guzzlehttp/ | 1.8.4 | 2 |
| ujamii/ | 6243197349e1 | guzzlehttp/ | 1.8.4 | 2 |
| conduction/ | 9cfeeb6c7c20 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | c36094a41369 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | ece1ab544c57 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | 25415534d245 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | 3423845692c1 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | 2744565516e8 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | e1d4ad1e22a8 | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | b6f95c8ead7d | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | 8f177f9f8a7b | guzzlehttp/ | 1.8.4 | 1 |
| conduction/ | 24f03c57568f | guzzlehttp/ | 1.8.4 | 1 |
| fireflyiii/ | 2f4283bd0cf7 | guzzlehttp/ | 2.1.1 | 1 |
| jordan/ | f75025fe8ea8 | guzzlehttp/ | 1.8.4 | 1 |
| library/ | 8a1a3ee83899 | guzzlehttp/ drupal/ | 1.8.4 9.2.16 | 1 |
| library/ | ceb1ba4196ab | guzzlehttp/ | 2.1.1 | 1 |
| library/ | 96104cb965fc | guzzlehttp/ | 1.8.4 | 1 |
| linuxserver/ | 291296e66c2a | guzzlehttp/ | 2.1.1 | 1 |
| lycheeorg/ | 308c0e6231da | guzzlehttp/ | 1.8.4 | 1 |
| openemr/ | 89eaa6d9a4e3 | guzzlehttp/ | 2.1.1 | 1 |
| pe46dro/ | 09dfe3aa10f6 | guzzlehttp/ | 1.8.4 | 1 |
| shlinkio/ | c6729db1d3a8 | guzzlehttp/ | 1.8.4 | 1 |
| shyim/ | a951c0e6b836 | guzzlehttp/ | 1.8.4 | 1 |
| solidnerd/ | 762ffd5c51d3 | guzzlehttp/ | 2.1.1 | 1 |
| wallabag/ | 5e4c26a7fb4a | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | c5075f0320cd | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 94a749392fcf | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | c17f1ba17d36 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 03aba499950f | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | deed102b4255 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 35225eaa87ab | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 4ffe222b3e3a | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 26d91dcbba56 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 834b8e1af290 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 72aae2080595 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | ef77f4c089a1 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | cd9656e6bc2c | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | c22764cbfa97 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | d17257e4fa27 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 956c4fb64796 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 7242da105081 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | eb36ead1954e | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | afe623824b82 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 04f1b7f0d573 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | f745e2870692 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | 66bbaf95a123 | guzzlehttp/ | 1.8.4 | 1 |
| ghcr.io/ | e918014fb8d3 | guzzlehttp/ | 1.8.4 | 1 |