StackRadar

CVE-2022-2509

High

Advisory

Published 1 Aug 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.019
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
613
of 17,787 indexed, latest versions
Container images
581
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: gnutls security update

Carried by container images the latest versions of 613 of 17,787 indexed charts deploy, on 581 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.5.17-1ubuntu1, 3.5.18-1ubuntu1, 3.5.18-1ubuntu1.1, 3.5.18-1ubuntu1.2+9 more3.5.18-1ubuntu1.6, 3.6.13-2ubuntu1.7, 3.7.1-5+deb11u2, 3.7.3-4ubuntu1.1469
gnutlsrpm3.6.5-2.el8, 3.6.7-14.4.1, 3.6.7-lp151.2.3.1, 3.6.8-8.el8+7 more0:3.6.16-5.el8_6, 3.6.7-150200.14.19.2, 3.7.7-1.186
gnutlsapk3.7.1-r0, 3.7.6-r03.7.1-r1, 3.7.7-r026
OSV records
ALPINE-CVE-2022-2509RHSA-2022:7105UBUNTU-CVE-2022-2509DSA-5203-1openSUSE-SU-2024:12233-1SUSE-SU-2022:2882-1
Also known as
USN-5550-1

Charts affected

613 by stars
ChartLatestAffected imagesRadar Score
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2

Open the chart page →

9,399
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7

Open the chart page →

14,420
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6

Open the chart page →

28,699
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
gnutls28@3.7.1-5
3.7.1-5+deb11u2

Open the chart page →

7,552
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6

Open the chart page →

10,857
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7

Open the chart page →

15,287
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gnutls@3.6.14-7.el8_3
0:3.6.16-5.el8_6

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6

Open the chart page →

6,138
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
gnutls@3.7.1-r0
3.7.1-r1

Open the chart page →

2,555
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2

Open the chart page →

1,585
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
gnutls28@3.7.1-5
3.7.1-5+deb11u2

Open the chart page →

2,021
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6

Open the chart page →

11,592
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6
yandex/clickhouse-server:21.3.204eccfffb01d7
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7

Open the chart page →

9,250

Container images carrying it

581 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
gnutls@3.7.1-r0
3.7.1-r1
1
ghcr.io/alexanderbabel/database-s3-backup:1.3.33191b771a6f2
gnutls@3.7.1-r0
3.7.1-r1
1
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/cfcontainerizationbot/kubecf-kubectl:v1.19.261daa1bba5cb
gnutls@3.6.7-14.4.1
3.6.7-150200.14.19.2
1
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/contactcatalogus-nginx:latest480c84fa9e63
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/digispoof-interface-nginx:latest8fa4597217a4
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/eav-component-nginx:latestd785c893096c
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/medewerkercatalogus-nginx:latest06c3b27462e6
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/skeleton-pip:devce1ebe9387a2
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/user-component-nginx:latestb721579df8c3
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/waardepapieren-nginx:latestaf31cf6cd59f
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
gnutls@3.7.1-r0
3.7.1-r1
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6
1
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
gnutls@3.7.1-r0
3.7.1-r1
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
gnutls@3.7.6-r0
3.7.7-r0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
gnutls@3.7.1-r0
3.7.1-r1
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
gnutls@3.6.8-11.el8_2
0:3.6.16-5.el8_6
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/justarchinet/archisteamfarm:5.2.5.4c7c0a52303cb
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.7
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.