StackRadar

CVE-2022-24785

High

Advisory

Published 4 Apr 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.055
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
114
of 17,781 indexed, latest versions
Container images
117
deployed by those charts
Fix available
1 of 1
affected package

Path Traversal: 'dir/../../filename' in moment.locale

Carried by container images the latest versions of 114 of 17,781 indexed charts deploy, on 117 images.

Affected packageAffected versionsFixed inImages
momentnpm2.1.0, 2.5.1, 2.19.4, 2.21.0+8 more2.29.2117
OSV records
GHSA-8hfj-j24r-96c4

Charts affected

114 by stars
ChartLatestAffected imagesRadar Score
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
moment@2.29.1
2.29.2

Open the chart page →

3,638
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
moment@2.29.1
2.29.2

Open the chart page →

2,460
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
moment@2.29.1
2.29.2

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
moment@2.29.1
2.29.2

Open the chart page →

2,121
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
moment@2.29.1
2.29.2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
moment@2.29.1
2.29.2

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
moment@2.29.1
2.29.2

Open the chart page →

3,881
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
moment@2.5.1
2.29.2

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
moment@2.24.0
2.29.2

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
moment@2.29.1
2.29.2

Open the chart page →

3,576
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
moment@2.24.0
2.29.2

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
moment@2.29.1
2.29.2

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
moment@2.27.0
2.29.2

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-24785.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
moment@2.24.0
2.29.2

Open the chart page →

5,806

Container images carrying it

117 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kubebb/tamp-portal:v5.6.0fadac6d52470
moment@2.29.1
2.29.2
1
kubebb/tdsf-portal:v5.7.0258458311bc9
moment@2.29.1
2.29.2
1
kubevious/guard:1.2.19bf567704de2
moment@2.29.1
2.29.2
1
kubevious/parser:1.0.151acf1a1f0b47
moment@2.29.1
2.29.2
1
library/ghost:6.25.12654b1e90413
moment@2.24.0
2.29.2
1
library/ghost:4.37.0767230c0f263
moment@2.24.0
2.29.2
1
library/ghost:5.79.083f7bf209844
moment@2.24.0
2.29.2
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
moment@2.24.0
2.29.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
moment@2.29.1
2.29.2
1
linuxserver/cloud9:latest45c5fe102ff3
moment@2.1.0
2.29.2
1
linuxserver/codimd:latestb801bbcf6386
moment@2.29.1
2.29.2
1
linuxserver/grocy:version-v3.1.3291296e66c2a
moment@2.29.1
2.29.2
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
moment@2.29.1
2.29.2
1
lsstsqre/prepuller:latest19c2dfc4e4ff
moment@2.29.1
2.29.2
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
moment@2.29.1
2.29.2
1
lsstsqre/wfdispatcher:lateste9feb99f524d
moment@2.29.1
2.29.2
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
moment@2.24.0
2.29.2
1
minddocdev/hubot:0.1.96c60b11a4fa7
moment@2.22.2
2.29.2
1
misskey/misskey:12.110.1e08b7c478093
moment@2.24.0
2.29.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
moment@2.27.0
2.29.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
moment@2.27.0
2.29.2
1
nodered/node-red:2.2.2e131dcadfe92
moment@2.29.1
2.29.2
1
nodered/node-red-docker:0.19.6-v8070643219ea2
moment@2.24.0
2.29.2
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
moment@2.29.1
2.29.2
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
moment@2.27.0
2.29.2
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
moment@2.24.0
2.29.2
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
moment@2.29.1
2.29.2
1
pawelmalak/flame:2.1.193e7b0abb603
moment@2.29.1
2.29.2
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
moment@2.29.1
2.29.2
1
polonel/trudesk:1.2.60cf6513f6fe3
moment@2.24.0
2.29.2
1
refar/apm-portal:v5.7.1dcca8e4477a6
moment@2.29.1
2.29.2
1
requarks/wiki:canary-2.5.2438b5865a7386c
moment@2.29.1
2.29.2
1
robotshop/rs-cart:latest388349d5cb3c
moment@2.29.1
2.29.2
1
robotshop/rs-catalogue:latestd545747c1b97
moment@2.29.1
2.29.2
1
robotshop/rs-user:latestea509182c180
moment@2.29.1
2.29.2
1
shinobisystems/shinobi:dev3ca746937856
moment@2.29.1
2.29.2
1
shinobisystems/shinobi:latestc2f5ce2e1067
moment@2.29.1
2.29.2
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
moment@2.29.1
2.29.2
1
slagattollas/server-practica:latest6dd8ead8e2b1
moment@2.29.1
2.29.2
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
moment@2.29.1
2.29.2
1
sqlpad/sqlpad:6.7d3d2f430dffd
moment@2.29.1
2.29.2
1
temporalio/web:1.14.033cfa863d8ce
moment@2.27.0
2.29.2
1
testhubio/testhub-frontend:on-preme86c2db53be8
moment@2.24.0
2.29.2
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
moment@2.29.1
2.29.2
1
tzahi12345/youtubedl-material:4.23720b856bd2f
moment@2.29.1
2.29.2
1
ubercadence/web:v3.29.58564a5b44a6d
moment@2.29.1
2.29.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
moment@2.29.1
2.29.2
1
wekanteam/wekan:v4.2268a51f0327df
moment@2.27.0
2.29.2
1
wiremind/scrapoxy:lateste7048929a676
moment@2.19.4
2.29.2
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
moment@2.29.1
2.29.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.