StackRadar

CVE-2022-25147

Medium

Advisory

Published 31 Jan 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
4 of 4
affected packages

Red Hat Security Advisory: apr-util security update

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
apr-utildeb1.6.1-4, 1.6.1-4ubuntu2, 1.6.1-51.6.1-4+deb10u1, 1.6.1-4ubuntu2.1, 1.6.1-5+deb11u1145
aprapk1.7.0-r0, 1.7.0-r1, 1.7.0-r21.7.1-r04
apr-utilapk1.6.1-r11, 1.6.1-r12, 1.6.1-r141.6.3-r04
apr-utilrpm1.6.1-6.el80:1.6.1-6.el8_8.11
OSV records
ALPINE-CVE-2022-25147RHSA-2023:3109UBUNTU-CVE-2022-25147DLA-3332-1DSA-5364-1
Also known as
USN-5870-1

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
tool-quickstatementswbstack0.4.01 of 1See more

tool-quickstatements wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-25147.

Container imageDigestPackageFixed in
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
apr-util@1.6.1-4
1.6.1-4+deb10u1

Open the chart page →

1,698
tool-widarwbstack0.4.01 of 1See more

tool-widar wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-25147.

Container imageDigestPackageFixed in
ghcr.io/wbstack/widar:1.31702fc9df79f
apr-util@1.6.1-4
1.6.1-4+deb10u1

Open the chart page →

1,480
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-25147.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
apr-util@1.6.1-5
1.6.1-5+deb11u1

Open the chart page →

9,397
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25147.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
apr-util@1.6.1-4
1.6.1-4+deb10u1

Open the chart page →

2,670
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-25147.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
apr-util@1.6.1-5
1.6.1-5+deb11u1

Open the chart page →

2,021

Container images carrying it

150 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
robotshop/rs-payment:latest774b52c6180d
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
robotshop/rs-ratings:latest4899c686c249
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
robotshop/rs-shipping:latest89753ab48919
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
samajh/alprbackend:latestea742b4372ad
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
samajh/alprfrontend:latest05ef4fddbb75
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
seataio/seata-server:latest703b5de7f1a6
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
shadow228/accountingcollege:0.0.28fcea5b71906
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
snipe/snipe-it:v6.0.1455fb7636a98c
apr-util@1.6.1-4ubuntu2
1.6.1-4ubuntu2.1
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
socialmediamacroscope/classification_train:0.1.207477060bba8
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
solidnerd/bookstack:21.12762ffd5c51d3
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apr-util@1.6.1-4ubuntu2
1.6.1-4ubuntu2.1
1
stakater/workshop-operator:v0.0.3897bf456cc97c
apr-util@1.6.1-6.el8
0:1.6.1-6.el8_8.1
1
stratospire/activityrelay:0.2.3a4c34cb01117
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
svtechnmaa/svtech_http_thruk:v1.0.2e19aba397c1f
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
vlebediantsev/config-server-another:lateste7f20450d2ae
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
vlebediantsev/logic-ms:latestdf8bf38c535b
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
vlebediantsev/registration-ms-final:latest427af418b75e
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
volkerraschek/postfixadmin:3.3.13c4f10aebf87b
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
weblate/weblate:3.11.3-182848df56ecd
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
xtrendence/cryptofolio:V.2.2.0e6e6612bb94c
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
zohardocker12/weather_app_flask:latestb86d60dbb68d
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apr-util@1.6.1-4ubuntu2
1.6.1-4ubuntu2.1
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
ghcr.io/privacyengineering/consumer:main73f59c032812
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/wbstack/cradle:2.0.11c7a78c54f77
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
ghcr.io/wbstack/widar:1.31702fc9df79f
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apr-util@1.6.1-4ubuntu2
1.6.1-4ubuntu2.1
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
apr-util@1.6.1-4
1.6.1-4+deb10u1
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
apr-util@1.6.1-5
1.6.1-5+deb11u1
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
apr-util@1.6.1-4
1.6.1-4+deb10u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.