StackRadar

CVE-2022-2582

Medium

Advisory

Published 1 Jul 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
114
of 17,781 indexed, latest versions
Container images
103
deployed by those charts
Fix available
1 of 1
affected package

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

Carried by container images the latest versions of 114 of 17,781 indexed charts deploy, on 103 images.

Affected packageAffected versionsFixed inImages
github.com/aws/aws-sdk-gogolangv1.12.54, v1.15.24, v1.17.7, v1.17.14+46 more1.34.0103
OSV records
GHSA-6jvc-q2x7-pchv
Also known as
GHSA-76wf-9vgp-pj7w, GO-2022-0391

Charts affected

114 by stars
ChartLatestAffected imagesRadar Score
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
github.com/aws/aws-sdk-go@v1.17.7
1.34.0

Open the chart page →

3,096
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
github.com/aws/aws-sdk-go@v1.33.5
1.34.0

Open the chart page →

2,564
cost-analyzerstatcan1.82.22 of 9See more

cost-analyzer statcan 1.82.2

2 of the 9 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
github.com/aws/aws-sdk-go@v1.28.9
1.34.0
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
github.com/aws/aws-sdk-go@v1.28.9
1.34.0

Open the chart page →

16,506
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/aws/aws-sdk-go@v1.29.20
1.34.0

Open the chart page →

12,237
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
github.com/aws/aws-sdk-go@v1.27.0
1.34.0

Open the chart page →

2,869
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
github.com/aws/aws-sdk-go@v1.27.0
1.34.0

Open the chart page →

2,821
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
github.com/aws/aws-sdk-go@v1.25.48
1.34.0

Open the chart page →

21,005
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
github.com/aws/aws-sdk-go@v1.29.20
1.34.0

Open the chart page →

3,191
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
github.com/aws/aws-sdk-go@v1.31.9
1.34.0

Open the chart page →

8,484
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/aws/aws-sdk-go@v1.29.16
1.34.0

Open the chart page →

4,382
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
github.com/aws/aws-sdk-go@v1.32.7
1.34.0

Open the chart page →

4,984
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
github.com/aws/aws-sdk-go@v1.25.48
1.34.0
prom/prometheus:v2.16.0e4ca62c0d62f
github.com/aws/aws-sdk-go@v1.25.48
1.34.0

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
github.com/aws/aws-sdk-go@v1.30.20
1.34.0

Open the chart page →

3,369
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-2582.

Container imageDigestPackageFixed in
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
github.com/aws/aws-sdk-go@v1.25.41
1.34.0

Open the chart page →

5,033

Container images carrying it

103 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/aws/aws-sdk-go@v1.31.6
1.34.0
1
quay.io/tigera/operator:v1.20.1379efe0c2541
github.com/aws/aws-sdk-go@v1.19.6
1.34.0
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
github.com/aws/aws-sdk-go@v1.19.6
1.34.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.