StackRadar

CVE-2022-25896

Medium

Advisory

Published 2 Jul 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
29
of 17,781 indexed, latest versions
Container images
28
deployed by those charts
Fix available
1 of 1
affected package

Passport vulnerable to session regeneration when a users logs in or out

Carried by container images the latest versions of 29 of 17,781 indexed charts deploy, on 28 images.

Affected packageAffected versionsFixed inImages
passportnpm0.3.0, 0.3.2, 0.4.0, 0.4.1+1 more0.6.028
OSV records
GHSA-v923-w3x8-wh69
Also known as
SNYK-JS-PASSPORT-2840631

Charts affected

29 by stars
ChartLatestAffected imagesRadar Score
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
passport@0.4.1
0.6.0

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
passport@0.3.2
0.6.0

Open the chart page →

5,946
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
passport@0.3.0
0.6.0

Open the chart page →

5,209
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
passport@0.4.1
0.6.0

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
passport@0.5.2
0.6.0

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
passport@0.5.2
0.6.0

Open the chart page →

15,653
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
passport@0.4.1
0.6.0

Open the chart page →

4,410
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
passport@0.4.1
0.6.0

Open the chart page →

3,833
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
passport@0.4.0
0.6.0

Open the chart page →

25,443
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
passport@0.3.0
0.6.0

Open the chart page →

18,277
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
passport@0.4.0
0.6.0

Open the chart page →

4,790
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
passport@0.3.0
0.6.0

Open the chart page →

5,209
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
passport@0.5.2
0.6.0

Open the chart page →

2,102
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
passport@0.3.2
0.6.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
passport@0.3.2
0.6.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
passport@0.3.2
0.6.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
passport@0.3.2
0.6.0

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
passport@0.4.1
0.6.0

Open the chart page →

8,213
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
passport@0.4.1
0.6.0

Open the chart page →

4,253
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
passport@0.4.0
0.6.0

Open the chart page →

39,349
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
passport@0.4.1
0.6.0

Open the chart page →

7,232
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
passport@0.4.1
0.6.0

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
passport@0.5.2
0.6.0

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
passport@0.4.1
0.6.0

Open the chart page →

5,410
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_server:0.3.31a528c794270
passport@0.4.1
0.6.0

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
passport@0.4.1
0.6.0

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
passport@0.4.1
0.6.0

Open the chart page →

9,968
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
passport@0.4.1
0.6.0

Open the chart page →

20,270
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
passport@0.4.1
0.6.0

Open the chart page →

3,576
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
passport@0.5.2
0.6.0

Open the chart page →

3,129
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
passport@0.4.1
0.6.0

Open the chart page →

22,665
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-25896.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
passport@0.4.1
0.6.0

Open the chart page →

5,459

Container images carrying it

28 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
passport@0.3.0
0.6.0
3
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
passport@0.4.1
0.6.0
2
requarks/wiki:2:latest68f0d1848261
passport@0.4.1
0.6.0
2
catalysm/csmm:latestf003b35f54d9
passport@0.4.1
0.6.0
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
passport@0.4.0
0.6.0
1
library/ghost:4.37.0767230c0f263
passport@0.5.2
0.6.0
1
linuxserver/codimd:latestb801bbcf6386
passport@0.4.1
0.6.0
1
nodered/node-red:2.2.2e131dcadfe92
passport@0.5.2
0.6.0
1
nodered/node-red-docker:0.19.6-v8070643219ea2
passport@0.4.0
0.6.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
passport@0.5.2
0.6.0
1
requarks/wiki:canary-2.5.2438b5865a7386c
passport@0.4.1
0.6.0
1
roadiehq/community-backstage-image:latestef355bf5b639
passport@0.4.1
0.6.0
1
samajh/alprbackend:latestea742b4372ad
passport@0.4.1
0.6.0
1
socialmediamacroscope/smile_server:0.3.31a528c794270
passport@0.4.1
0.6.0
1
sqlpad/sqlpad:6.7d3d2f430dffd
passport@0.4.1
0.6.0
1
stanfordoval/almond-server:latest1a63cdccedaf
passport@0.5.2
0.6.0
1
temporalio/web:1.14.033cfa863d8ce
passport@0.4.1
0.6.0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
passport@0.4.1
0.6.0
1
tzahi12345/youtubedl-material:4.23720b856bd2f
passport@0.4.1
0.6.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
passport@0.3.2
0.6.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
passport@0.3.2
0.6.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
passport@0.3.2
0.6.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
passport@0.3.2
0.6.0
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
passport@0.4.1
0.6.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
passport@0.3.2
0.6.0
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
passport@0.5.2
0.6.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
passport@0.4.1
0.6.0
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
passport@0.4.0
0.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.