StackRadar

CVE-2022-24834

High

Advisory

Published 13 Jul 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.414
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
4 of 4
affected packages

Heap overflow issue with the Lua cjson library used by Redis

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
redisbitnami6.0.8-0, 6.0.12-0, 6.2.7-150, 7.0.8-0+3 more6.0.207
redisapk7.0.4-r07.0.12-r01
lua-cjsondeb2.1.0+dfsg-2.12.1.0+dfsg-2.1ubuntu0.20.04.1~esm22
redisdeb5:5.0.7-2ubuntu0.15:5.0.7-2ubuntu0.1+esm22
OSV records
ALPINE-CVE-2022-24834BIT-redis-2022-24834UBUNTU-CVE-2022-24834
Also known as
BIT-keydb-2022-24834, BIT-valkey-2022-24834, GHSA-p8x2-9v9q-c838, USN-6531-1, USN-8169-1

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
redis@7.0.11-1
6.0.20

Open the chart page →

22,002
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
redis@6.2.7-150
6.0.20

Open the chart page →

9,203
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
netrisai/redis:6.0.12-debian-10-r3a4c0140d1696
redis@6.0.12-0
6.0.20

Open the chart page →

30,326
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
redis@7.0.10-0
6.0.20

Open the chart page →

9,847
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
lua-cjson@2.1.0+dfsg-2.1
redis@5:5.0.7-2ubuntu0.1
2.1.0+dfsg-2.1ubuntu0.20.04.1~esm2
5:5.0.7-2ubuntu0.1+esm2

Open the chart page →

20,933
redisredisVerified publisher0.1.11 of 1See more

redis redis 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/bitnami/redis:6.0.8.9e1e9cf5297a6
redis@6.0.8-0
6.0.20

Open the chart page →

1,594
redisredis-arm17.8.01 of 1See more

redis redis-arm 17.8.0

1 of the 1 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
redis@7.0.8-1
6.0.20

Open the chart page →

1,906
redis-high-availabilitysomeblackmagic1.3.101 of 3See more

redis-high-availability someblackmagic 1.3.10

1 of the 3 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
redis@7.0.8-0
6.0.20

Open the chart page →

3,148
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
lua-cjson@2.1.0+dfsg-2.1
redis@5:5.0.7-2ubuntu0.1
2.1.0+dfsg-2.1ubuntu0.20.04.1~esm2
5:5.0.7-2ubuntu0.1+esm2

Open the chart page →

30,687
webapp-chartwebappchart1.0.01 of 1See more

webapp-chart webappchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-24834.

Container imageDigestPackageFixed in
amagdi888/my-repo:hello-appd8a10fc8faf6
redis@7.0.4-r0
7.0.12-r0

Open the chart page →

1,201

Container images carrying it

10 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
amagdi888/my-repo:hello-appd8a10fc8faf6
redis@7.0.4-r0
7.0.12-r0
1
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
redis@7.0.11-1
6.0.20
1
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
redis@7.0.10-0
6.0.20
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
redis@6.2.7-150
6.0.20
1
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
redis@7.0.8-0
6.0.20
1
netrisai/redis:6.0.12-debian-10-r3a4c0140d1696
redis@6.0.12-0
6.0.20
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
lua-cjson@2.1.0+dfsg-2.1
redis@5:5.0.7-2ubuntu0.1
2.1.0+dfsg-2.1ubuntu0.20.04.1~esm2
5:5.0.7-2ubuntu0.1+esm2
1
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
redis@7.0.8-1
6.0.20
1
mcr.microsoft.com/oss/bitnami/redis:6.0.8.9e1e9cf5297a6
redis@6.0.8-0
6.0.20
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
lua-cjson@2.1.0+dfsg-2.1
redis@5:5.0.7-2ubuntu0.1
2.1.0+dfsg-2.1ubuntu0.20.04.1~esm2
5:5.0.7-2ubuntu0.1+esm2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.