StackRadar

CVE-2022-24999

High

Advisory

Published 26 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.151
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
289
of 17,781 indexed, latest versions
Container images
283
deployed by those charts
Fix available
2 of 2
affected packages

qs vulnerable to Prototype Pollution

Carried by container images the latest versions of 289 of 17,781 indexed charts deploy, on 283 images.

Affected packageAffected versionsFixed inImages
qsnpm0.5.6, 0.6.5, 1.2.2, 2.2.4+16 more6.2.4, 6.3.3, 6.4.1, 6.5.3+4 more283
node-qsdeb6.9.1+ds-16.9.1+ds-1ubuntu0.1~esm12
OSV records
GHSA-hrpp-h998-j3ppUBUNTU-CVE-2022-24999
Also known as
USN-7693-1

Charts affected

289 by stars
ChartLatestAffected imagesRadar Score
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
qs@6.9.3
6.9.7

Open the chart page →

3,118
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
qs@6.4.0
6.4.1

Open the chart page →

3,638
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
qs@2.3.3
6.2.4

Open the chart page →

2,638
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
qs@6.5.2
6.5.3

Open the chart page →

3,696
simple-db-app-chartsimple-db-app0.1.01 of 2See more

simple-db-app-chart simple-db-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
qs@6.9.6
6.9.7

Open the chart page →

1,925
simple-db-app-chart-with-dependencysimple-db-app0.1.01 of 3See more

simple-db-app-chart-with-dependency simple-db-app 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
qs@6.9.6
6.9.7

Open the chart page →

1,925
first-appsimple-helm-chart0.1.01 of 1See more

first-app simple-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
leeyoongti/first-app:1.0.021d66cb76352
qs@6.7.0
6.7.3

Open the chart page →

2,154
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
qs@6.5.2
6.5.3

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
qs@6.5.2
6.5.3

Open the chart page →

29,220
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
qs@6.7.0
6.7.3

Open the chart page →

2,460
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
qs@6.7.0
6.7.3

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
qs@6.10.1
6.10.3

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
qs@6.10.1
6.10.3

Open the chart page →

1,890
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
qs@6.7.0
6.7.3

Open the chart page →

11,100
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
qs@6.5.2
6.5.3

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
qs@6.5.2
6.5.3

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
qs@6.5.2
6.5.3

Open the chart page →

3,881
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
qs@6.5.2
6.5.3

Open the chart page →

4,967
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
qs@5.2.1
6.2.4

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
qs@5.2.1
6.2.4

Open the chart page →

12,460
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-qs@6.9.1+ds-1
qs@6.9.1
6.9.1+ds-1ubuntu0.1~esm1
6.9.7

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
qs@6.5.2
6.5.3

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
qs@6.5.2
6.5.3

Open the chart page →

4,017
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
qs@6.7.0
6.7.3

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
qs@6.7.0
6.7.3

Open the chart page →

3,576
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
qs@6.5.2
6.5.3

Open the chart page →

6,881
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
qs@6.5.2
6.5.3

Open the chart page →

5,535
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
qs@6.9.3
6.9.7

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
qs@6.5.2
6.5.3

Open the chart page →

3,129
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
qs@6.9.3
6.9.7

Open the chart page →

3,118
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
qs@6.5.2
6.5.3

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
qs@6.10.1
6.10.3

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
qs@6.10.1
6.10.3

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
qs@6.5.2
6.5.3

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
qs@6.5.2
6.5.3

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
qs@6.5.2
6.5.3

Open the chart page →

5,806
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
qs@6.7.0
6.7.3

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
qs@6.5.2
6.5.3

Open the chart page →

1,309
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
qs@6.5.2
6.5.3

Open the chart page →

3,118

Container images carrying it

283 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
leeyoongti/first-app:1.0.021d66cb76352
qs@6.7.0
6.7.3
1
library/ghost:4.37.0767230c0f263
qs@6.9.6
6.9.7
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
qs@6.5.2
6.5.3
1
linuxserver/cloud9:latest45c5fe102ff3
qs@6.4.0
6.4.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
qs@6.7.0
6.7.3
1
linuxserver/codimd:latestb801bbcf6386
qs@6.5.2
6.5.3
1
linuxserver/grocy:version-v3.1.3291296e66c2a
qs@6.5.2
6.5.3
1
lissy93/dashy:2.0.51991f7be5ed0
qs@6.9.6
6.9.7
1
logentries/docker-logentries:0.2.1f1f90a236998
qs@6.2.1
6.2.4
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-qs@6.9.1+ds-1
qs@6.9.1
6.9.1+ds-1ubuntu0.1~esm1
6.9.7
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
qs@6.2.1
6.2.4
1
lsstsqre/squareone:0.4.09ded78e7fe03
qs@6.5.2
6.5.3
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
qs@6.5.2
6.5.3
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
qs@6.5.2
6.5.3
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
qs@6.5.2
6.5.3
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
qs@6.4.0
6.4.1
1
milesmcc/shynet:v0.13.1ba54f7797a6b
qs@6.5.2
6.5.3
1
milesmcc/shynet:v0.12.0e821e31140f7
qs@6.5.2
6.5.3
1
minddocdev/hubot:0.1.96c60b11a4fa7
qs@6.5.2
6.5.3
1
misskey/misskey:12.110.1e08b7c478093
qs@6.7.0
6.7.3
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
qs@6.5.2
6.5.3
1
mozilla/sentencecollector:2.0.91da6ff5c4895
qs@6.5.2
6.5.3
1
muluder/prograncontrollermcord:0.1.843b597a93da7
qs@6.5.1
6.5.3
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
qs@6.7.0
6.7.3
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
qs@6.5.2
6.5.3
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
qs@6.5.2
6.5.3
1
nodered/node-red:2.2.2e131dcadfe92
qs@6.5.2
6.5.3
1
nodered/node-red-docker:0.19.6-v8070643219ea2
qs@6.5.2
6.5.3
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
qs@6.10.2
6.10.3
1
omecproject/onos-progran:1.0.05715e5648aa0
qs@6.5.1
6.5.3
1
ondrejsika/parking:latestb1fd497416c8
qs@6.5.2
6.5.3
1
openproject/community:12.0.2734743d11094
qs@6.5.2
6.5.3
1
openthread/otbr:latestf307f59f6432
qs@2.2.4
6.2.4
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
qs@6.5.2
6.5.3
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
qs@2.2.4
6.2.4
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
qs@6.7.0
6.7.3
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
qs@6.5.2
6.5.3
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
qs@2.3.3
6.2.4
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
qs@6.5.2
6.5.3
1
pawelmalak/flame:2.1.193e7b0abb603
qs@6.7.0
6.7.3
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
qs@6.5.2
6.5.3
1
phntom/camo:2.3.1a9b1304d6c71
qs@6.5.2
6.5.3
1
phntom/codimd:2.4.31b9aafbb62e6
qs@6.5.2
6.5.3
1
plumdog/db-operator:latest0c2fa2db0357
qs@6.5.2
6.5.3
1
polonel/trudesk:1.2.60cf6513f6fe3
qs@6.5.2
6.5.3
1
project2team4/react:latest3ff031a08887
qs@6.5.2
6.5.3
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
qs@6.5.2
6.5.3
1
pysga1996/python-redis-web:latestfdeec30ad482
qs@6.7.0
6.7.3
1
rakii8585/angular-node-webapp:latest026082a515ac
qs@6.7.0
6.7.3
1
refar/apm-portal:v5.7.1dcca8e4477a6
qs@6.5.2
6.5.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.