StackRadar

CVE-2022-29217

High

Advisory

Published 24 May 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
81
of 17,781 indexed, latest versions
Container images
68
deployed by those charts
Fix available
2 of 2
affected packages

Key confusion through non-blocklisted public key formats

Carried by container images the latest versions of 81 of 17,781 indexed charts deploy, on 68 images.

Affected packageAffected versionsFixed inImages
pyjwtdeb2.3.0-12.3.0-1ubuntu0.11
pyjwtpypi1.5.3, 1.6.1, 1.6.4, 1.7.0+5 more2.4.068
OSV records
GHSA-ffqj-6fqr-9h24UBUNTU-CVE-2022-29217
Also known as
PYSEC-2022-202, USN-5526-1, USN-5526-2

Charts affected

81 by stars
ChartLatestAffected imagesRadar Score
forms-catalogueforms-catalogue0.1.01 of 2See more

forms-catalogue forms-catalogue 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pyjwt@1.7.1
2.4.0

Open the chart page →

2,188
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pyjwt@2.1.0
2.4.0

Open the chart page →

24,293
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
pyjwt@1.7.1
2.4.0

Open the chart page →

4,422
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pyjwt@1.7.1
2.4.0

Open the chart page →

7,984
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
pyjwt@1.7.1
2.4.0

Open the chart page →

37,671
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pyjwt@1.7.1
2.4.0

Open the chart page →

6,501
redashinseefrlab2.1.01 of 3See more

redash inseefrlab 2.1.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
redash/redash:10.0.0.b503639392753c0376
pyjwt@1.7.1
2.4.0

Open the chart page →

3,314
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
pyjwt@1.7.1
2.4.0

Open the chart page →

3,999
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
pyjwt@1.7.1
2.4.0

Open the chart page →

12,527
elastalert2kfirfer2.2.51 of 1See more

elastalert2 kfirfer 2.2.5

1 of the 1 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
jertel/elastalert2:2.2.34dcc0ef93efc
pyjwt@1.7.1
2.4.0

Open the chart page →

1,598
nubladolsst-sqre0.9.233 of 5See more

nublado lsst-sqre 0.9.23

3 of the 5 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
lsstsqre/prepuller:latest19c2dfc4e4ff
pyjwt@2.1.0
2.4.0
lsstsqre/sciplat-hub:latest5e0ade6bed1c
pyjwt@2.0.1
2.4.0
lsstsqre/wfdispatcher:lateste9feb99f524d
pyjwt@2.0.1
2.4.0

Open the chart page →

5,786
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
pyjwt@1.7.1
2.4.0

Open the chart page →

12,847
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pyjwt@2.1.0
2.4.0

Open the chart page →

22,084
request-registryrequest-registry0.1.01 of 2See more

request-registry request-registry 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pyjwt@1.7.1
2.4.0

Open the chart page →

2,201
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0
2.4.0

Open the chart page →

7,295
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
pyjwt@1.7.0
2.4.0

Open the chart page →

4,744
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pyjwt@1.7.1
2.4.0

Open the chart page →

8,694
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,803
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

24,776
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

24,776
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
pyjwt@1.7.1
2.4.0

Open the chart page →

25,769
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0
2.4.0

Open the chart page →

13,459
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.4.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-29217.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyjwt@1.6.1
2.4.0

Open the chart page →

11,784

Container images carrying it

68 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
seafileltd/seafile-mc:9.0.106693911bcc40
pyjwt@2.1.0
2.4.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
pyjwt@2.1.0
2.4.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pyjwt@2.1.0
2.4.0
1
statcan/ckan:2.93921305425b8
pyjwt@1.7.1
2.4.0
1
taigaio/taiga-back:6.4.29f97323cc150
pyjwt@2.1.0
2.4.0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pyjwt@2.3.0
2.4.0
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pyjwt@2.3.0
2.4.0
1
timescale/timescaledb-ha:pg16d7db8f1085a3
pyjwt@2.3.0
2.4.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pyjwt@2.3.0
2.4.0
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
pyjwt@2.3.0-1
pyjwt@2.3.0
2.3.0-1ubuntu0.1
2.4.0
1
trueosiris/vrising:latest9356f98ad561
pyjwt@2.3.0
2.4.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
pyjwt@2.3.0
2.4.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pyjwt@2.3.0
2.4.0
1
weblate/weblate:3.11.3-182848df56ecd
pyjwt@1.7.1
2.4.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pyjwt@2.3.0
2.4.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pyjwt@2.3.0
2.4.0
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
pyjwt@1.7.1
2.4.0
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
pyjwt@1.7.1
2.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.