StackRadar

CVE-2022-29078

Critical

Advisory

Published 26 Apr 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.328
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
48
deployed by those charts
Fix available
1 of 1
affected package

ejs template injection vulnerability

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 48 images.

Affected packageAffected versionsFixed inImages
ejsnpm0.8.8, 1.0.0, 2.3.4, 2.5.6+7 more3.1.748
OSV records
GHSA-phwq-j96m-2c2q

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
ejs@2.6.2
3.1.7

Open the chart page →

30,326
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
ejs@3.1.6
3.1.7

Open the chart page →

5,251
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
ejs@2.7.4
3.1.7

Open the chart page →

22,773
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
ejs@3.1.6
3.1.7

Open the chart page →

3,476
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ejs@0.8.8
3.1.7

Open the chart page →

5,209
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ejs@2.7.1
3.1.7

Open the chart page →

6,868
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
ejs@3.1.6
3.1.7

Open the chart page →

4,260
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
ejs@3.1.6
3.1.7

Open the chart page →

7,801
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ejs@2.7.4
3.1.7

Open the chart page →

3,143
statsdstatsd-airflow-smd0.1.191 of 1See more

statsd statsd-airflow-smd 0.1.19

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
ejs@2.7.4
3.1.7

Open the chart page →

4,185
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
ejs@2.7.4
3.1.7

Open the chart page →

7,517
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
ejs@0.8.8
3.1.7

Open the chart page →

3,437
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ejs@0.8.8
3.1.7

Open the chart page →

18,277
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
ejs@2.7.4
3.1.7

Open the chart page →

12,907
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ejs@0.8.8
3.1.7

Open the chart page →

5,209
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
ejs@2.7.4
3.1.7

Open the chart page →

3,744
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
ejs@2.7.4
3.1.7

Open the chart page →

3,159
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ejs@2.7.4
3.1.7

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
ejs@2.7.4
3.1.7

Open the chart page →

4,591
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ejs@3.0.1
3.1.7

Open the chart page →

3,642
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
ejs@2.6.1
3.1.7

Open the chart page →

24,161
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ejs@2.6.2
3.1.7

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
ejs@2.5.8
3.1.7

Open the chart page →

57,669
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
ejs@2.3.4
3.1.7

Open the chart page →

6,454
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
ejs@2.7.4
3.1.7

Open the chart page →

4,667
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
ejs@2.7.4
3.1.7

Open the chart page →

4,185
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
ejs@3.1.6
3.1.7

Open the chart page →

4,230
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
kubebb/tamp-portal:v5.6.0fadac6d52470
ejs@2.7.4
3.1.7

Open the chart page →

4,664
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
refar/apm-portal:v5.7.1dcca8e4477a6
ejs@2.7.4
3.1.7

Open the chart page →

10,264
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
kubebb/tdsf-portal:v5.7.0258458311bc9
ejs@2.7.4
3.1.7

Open the chart page →

6,490
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
ejs@3.1.6
3.1.7

Open the chart page →

5,905
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
ejs@2.7.4
3.1.7

Open the chart page →

3,651
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.7

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.7

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ejs@2.7.4
3.1.7

Open the chart page →

12,108
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ejs@2.7.4
3.1.7
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ejs@2.7.4
3.1.7
mojaloop/role-assignment-service:v2.1.0def4bf273721
ejs@2.7.4
3.1.7

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ejs@2.7.4
3.1.7

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.7
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ejs@2.7.4
3.1.7
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ejs@2.7.4
3.1.7

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ejs@2.7.4
3.1.7

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ejs@2.7.4
3.1.7

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
ejs@2.7.4
3.1.7

Open the chart page →

2,316
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ejs@2.7.4
3.1.7

Open the chart page →

6,438
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
ejs@2.7.4
3.1.7

Open the chart page →

3,269
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
ejs@1.0.0
3.1.7
linuxserver/codimd:latestb801bbcf6386
ejs@2.7.4
3.1.7

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ejs@3.1.6
3.1.7

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
ejs@2.6.2
3.1.7

Open the chart page →

6,524
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ejs@2.7.4
3.1.7

Open the chart page →

5,215
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
ejs@2.5.6
3.1.7

Open the chart page →

3,638
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ejs@2.7.4
3.1.7

Open the chart page →

3,143
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2022-29078.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ejs@3.1.6
3.1.7

Open the chart page →

11,100

Container images carrying it

48 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ejs@2.7.4
3.1.7
3
pantsel/konga:latestc8172b75607d
ejs@0.8.8
3.1.7
3
hookiesolutions/webhookie:latest0629694246ba
ejs@3.1.6
3.1.7
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ejs@2.7.4
3.1.7
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ejs@2.7.4
3.1.7
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ejs@2.7.4
3.1.7
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ejs@2.7.4
3.1.7
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
ejs@2.7.4
3.1.7
2
statsd/statsd:v0.8.6dab129e74c25
ejs@2.7.4
3.1.7
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ejs@2.7.4
3.1.7
2
arfath29/3-tier-app-frontend:latest384b3e377f47
ejs@2.7.4
3.1.7
1
catalysm/csmm:latestf003b35f54d9
ejs@3.1.6
3.1.7
1
conduction/conduction-ui-app:devd591f5e6f2a9
ejs@2.7.4
3.1.7
1
fiware/idm:8.3.3a1b6ed4ae84f
ejs@2.7.4
3.1.7
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ejs@2.7.1
3.1.7
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
ejs@2.6.2
3.1.7
1
gristlabs/grist:0.7.96e71b1914a7e
ejs@2.7.4
3.1.7
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ejs@3.0.1
3.1.7
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
ejs@2.6.2
3.1.7
1
ibmcom/microclimate-portal:latested5505e5c7ec
ejs@2.5.8
3.1.7
1
jayfong/yapi:1.10.2163e5d621910
ejs@2.3.4
3.1.7
1
kubebb/tamp-portal:v5.6.0fadac6d52470
ejs@2.7.4
3.1.7
1
kubebb/tdsf-portal:v5.7.0258458311bc9
ejs@2.7.4
3.1.7
1
lavandadelpatio/frontend:latest501c3f31e0bc
ejs@2.7.4
3.1.7
1
library/ghost:4.37.0767230c0f263
ejs@3.1.6
3.1.7
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
ejs@2.7.4
3.1.7
1
linuxserver/cloud9:latest45c5fe102ff3
ejs@1.0.0
3.1.7
1
linuxserver/codimd:latestb801bbcf6386
ejs@2.7.4
3.1.7
1
lissy93/dashy:2.0.51991f7be5ed0
ejs@2.7.4
3.1.7
1
misskey/misskey:12.110.1e08b7c478093
ejs@3.1.6
3.1.7
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ejs@2.7.4
3.1.7
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
ejs@3.1.6
3.1.7
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
ejs@0.8.8
3.1.7
1
phntom/codimd:2.4.31b9aafbb62e6
ejs@2.6.2
3.1.7
1
refar/apm-portal:v5.7.1dcca8e4477a6
ejs@2.7.4
3.1.7
1
samajh/alprbackend:latestea742b4372ad
ejs@2.7.4
3.1.7
1
samajh/alprfrontend:latest05ef4fddbb75
ejs@2.7.4
3.1.7
1
shinobisystems/shinobi:dev3ca746937856
ejs@2.7.4
3.1.7
1
shinobisystems/shinobi:latestc2f5ce2e1067
ejs@2.7.4
3.1.7
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ejs@3.1.6
3.1.7
1
testhubio/testhub-frontend:on-preme86c2db53be8
ejs@2.7.4
3.1.7
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
ejs@3.1.6
3.1.7
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
ejs@3.1.6
3.1.7
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
ejs@3.1.6
3.1.7
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
ejs@2.6.1
3.1.7
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ejs@3.1.6
3.1.7
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ejs@2.7.4
3.1.7
1
quay.io/wekan/wekan:v5.65cb17600883a3
ejs@2.5.6
3.1.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.