StackRadar

CVE-2022-24795

Medium

Advisory

Published 5 Apr 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
2 of 3
affected packages

Buffer Overflow in yajl-ruby

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
yajl-rubygem1.3.1, 1.4.1, 1.4.21.4.311
yajldeb2.0.4-4, 2.0.4+wb-99+wallarm4.6.0+1, 2.1.0-2build1, 2.1.0-32.0.4-4ubuntu0.1~esm1, 2.1.0-2ubuntu0.18.04.1~esm1, 2.1.0-3ubuntu0.20.04.15
php-mongodbdeb2.1.4-4+ubuntu24.04.1+deb.sury.org+1no fix listed1
OSV records
GHSA-jj47-x69x-mxrmUBUNTU-CVE-2022-24795
Also known as
USN-6233-1, USN-6233-2

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
efkcryptexlabsVerified publisher7.17.31 of 3See more

efk cryptexlabs 7.17.3

1 of the 3 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.12.4-debian-elasticsearch7-1.0656423b5fabb
yajl-ruby@1.4.1
1.4.3

Open the chart page →

1,299
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
php-mongodb@2.1.4-4+ubuntu24.04.1+deb.sury.org+1
no fix listed

Open the chart page →

23,964
fluentdbryanalves0.1.01 of 1See more

fluentd bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
bryanalves/fluentd:0.5d3605be4b178
yajl-ruby@1.4.1
1.4.3

Open the chart page →

723
fluentd-cloudwatchcloudnativeapp0.9.01 of 2See more

fluentd-cloudwatch cloudnativeapp 0.9.0

1 of the 2 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
yajl-ruby@1.4.1
1.4.3

Open the chart page →

1,342
fluentd-kubernetes-awscloudposse0.2.11 of 2See more

fluentd-kubernetes-aws cloudposse 0.2.1

1 of the 2 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
yajl-ruby@1.4.1
1.4.3

Open the chart page →

1,305
galaxy-stablecloudve2.0.02 of 5See more

galaxy-stable cloudve 2.0.0

2 of the 5 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
yajl@2.0.4-4
2.0.4-4ubuntu0.1~esm1
galaxy/galaxy-stable:v18.018e577a626dfd
yajl@2.0.4-4
2.0.4-4ubuntu0.1~esm1

Open the chart page →

70,895
coralogix-fluentddevtron1.0.31 of 1See more

coralogix-fluentd devtron 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
yajl-ruby@1.4.1
1.4.3

Open the chart page →

750
coralogix-fluentddevtron-labs1.0.31 of 1See more

coralogix-fluentd devtron-labs 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
yajl-ruby@1.4.1
1.4.3

Open the chart page →

750
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
yajl@2.1.0-3
2.1.0-3ubuntu0.20.04.1

Open the chart page →

27,949
gwangju_2-3gwangju2-30.1.01 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

1 of the 5 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
yajl-ruby@1.4.1
1.4.3

Open the chart page →

6,491
fluentdhelm0.2.161 of 1See more

fluentd helm 0.2.16

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.14.0-debian-elasticsearch7-1.03933cae61054
yajl-ruby@1.4.1
1.4.3

Open the chart page →

1,217
coralogix-fluentdhelmtest1.0.41 of 1See more

coralogix-fluentd helmtest 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
yajl-ruby@1.4.1
1.4.3

Open the chart page →

750
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
yajl@2.1.0-2build1
2.1.0-2ubuntu0.18.04.1~esm1

Open the chart page →

12,611
fluentd-papertrailmozilla0.2.21 of 1See more

fluentd-papertrail mozilla 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
yajl-ruby@1.4.1
1.4.3

Open the chart page →

1,001
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
yajl-ruby@1.3.1
1.4.3

Open the chart page →

9,542
pecanncsaVerified publisher0.6.21 of 15See more

pecan ncsa 0.6.2

1 of the 15 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
yajl-ruby@1.3.1
1.4.3

Open the chart page →

14,154
coralogix-fluentdromholdings1.0.31 of 1See more

coralogix-fluentd romholdings 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
yajl-ruby@1.4.1
1.4.3

Open the chart page →

750
fluentdslamdev0.0.61 of 1See more

fluentd slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
yajl-ruby@1.4.1
1.4.3

Open the chart page →

1,384
velero-notificationsvelero-notifications1.1.01 of 1See more

velero-notifications velero-notifications 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
yajl-ruby@1.4.2
1.4.3

Open the chart page →

1,285
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2022-24795.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
yajl@2.0.4+wb-99+wallarm4.6.0+1
2.1.0-3ubuntu0.20.04.1

Open the chart page →

11,405

Container images carrying it

17 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
coralogixrepo/fluentd-coralogix-image:1.1.6b976e0412424
yajl-ruby@1.4.1
1.4.3
4
pecan/bety:5.4.1f825d480cd62
yajl-ruby@1.3.1
1.4.3
2
bryanalves/fluentd:0.5d3605be4b178
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:v1.11.5-debian-forward-1.00717111a3362
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:v1.3.3-debian-cloudwatch-1.017398121d3cc
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:v1.10.3-debian-cloudwatch-1.019a8f0662241
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:v1.14.0-debian-elasticsearch7-1.03933cae61054
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:v1.12.4-debian-elasticsearch7-1.0656423b5fabb
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:papertrail9c209835eea1
yajl-ruby@1.4.1
1.4.3
1
fluent/fluentd-kubernetes-daemonset:v1.4.2-debian-elasticsearch-1.1ce4885865850
yajl-ruby@1.4.1
1.4.3
1
galaxy/galaxy-init:v18.010267bad550e6
yajl@2.0.4-4
2.0.4-4ubuntu0.1~esm1
1
galaxy/galaxy-stable:v18.018e577a626dfd
yajl@2.0.4-4
2.0.4-4ubuntu0.1~esm1
1
ibmcom/skydive:0.22.0395e60cc6e3d
yajl@2.1.0-2build1
2.1.0-2ubuntu0.18.04.1~esm1
1
openkm/openkm-ce:6.3.113bc465a7461b
yajl@2.1.0-3
2.1.0-3ubuntu0.20.04.1
1
qonstrukt/php:8.4-v8-apache089af7925aa1
php-mongodb@2.1.4-4+ubuntu24.04.1+deb.sury.org+1
no fix listed
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
yajl@2.0.4+wb-99+wallarm4.6.0+1
2.1.0-3ubuntu0.20.04.1
1
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
yajl-ruby@1.4.2
1.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.