StackRadar

CVE-2022-29244

High

Advisory

Published 2 Jun 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.039
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
72
of 17,781 indexed, latest versions
Container images
71
deployed by those charts
Fix available
1 of 2
affected packages

Packing does not respect root-level ignore files in workspaces

Carried by container images the latest versions of 72 of 17,781 indexed charts deploy, on 71 images.

Affected packageAffected versionsFixed inImages
npmnpm7.11.2, 7.13.0, 7.15.1, 7.17.0+16 more8.11.065
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2no fix listed6
OSV records
GHSA-hj9c-8jmm-8c52UBUNTU-CVE-2022-29244

Charts affected

72 by stars
ChartLatestAffected imagesRadar Score
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
npm@7.19.1
8.11.0

Open the chart page →

5,287
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
npm@8.5.5
8.11.0

Open the chart page →

29,588
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
npm@8.1.3
8.11.0

Open the chart page →

43,341
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
npm@8.5.5
8.11.0

Open the chart page →

14,809
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
npm@8.5.5
8.11.0

Open the chart page →

1,661
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
npm@8.1.0
8.11.0

Open the chart page →

6,438
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
npm@8.3.1
8.11.0

Open the chart page →

1,130
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
npm@8.1.2
8.11.0

Open the chart page →

3,269
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
npm@7.19.1
8.11.0
socialmediamacroscope/smile_server:0.3.31a528c794270
npm@7.19.1
8.11.0

Open the chart page →

109,294
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
no fix listed

Open the chart page →

36,215
blockscoutparadeum-teamVerified publisher0.1.51 of 1See more

blockscout paradeum-team 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
quay.io/netwarps/blockscoutdigest-pinnedbecd3e39360a
npm@8.1.3
8.11.0

Open the chart page →

3,448
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
npm@7.17.0
8.11.0

Open the chart page →

5,687
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
npm@8.0.0
8.11.0

Open the chart page →

3,638
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
npm@8.1.2
8.11.0

Open the chart page →

3,143
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
npm@7.24.0
8.11.0

Open the chart page →

3,228
workshop-exercisestakaterVerified publisher0.0.2601 of 1See more

workshop-exercise stakater 0.0.260

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
stakater/workshop-exercise:0.0.26076926b7159d3
npm@8.5.0
8.11.0

Open the chart page →

992
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
npm@6.14.4+ds-1ubuntu2
no fix listed

Open the chart page →

10,902
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
npm@8.5.0
8.11.0

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
npm@8.5.0
8.11.0
samajh/alprfrontend:latest05ef4fddbb75
npm@8.5.0
8.11.0

Open the chart page →

20,270
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
npm@8.1.0
8.11.0

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
npm@8.1.0
8.11.0

Open the chart page →

28,605
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-29244.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
npm@8.1.2
8.11.0

Open the chart page →

3,118

Container images carrying it

71 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hookiesolutions/webhookie:latest0629694246ba
npm@8.1.0
8.11.0
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
npm@8.5.5
8.11.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
npm@8.5.0
8.11.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
npm@8.1.2
8.11.0
2
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
npm@8.9.0
8.11.0
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
npm@7.11.2
8.11.0
1
arturisimo/server-urjc:v1.0d8dc4430531e
npm@8.5.0
8.11.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
npm@8.5.5
8.11.0
1
blockscout/blockscout:5.1.5c365a8f2dc12
npm@8.10.0
8.11.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
npm@7.20.3
8.11.0
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
no fix listed
1
ethersphere/onboarding-faucet:0.3.0513154aab230
npm@8.5.5
8.11.0
1
ethpandaops/blobscan:latest7a9ab6370657
npm@8.1.2
8.11.0
1
fanzynoodle/smeejas:0.0.15f9916c1a287
npm@8.3.0
8.11.0
1
felddy/foundryvtt:0.8.36c5d90b90349
npm@7.11.2
8.11.0
1
frappe/frappe-socketio:v13.4.12095767a9e82
npm@7.15.1
8.11.0
1
gonzague/monopoly:latest70465995deea
npm@8.3.1
8.11.0
1
gtato/demo-multiclus-registrator:1.0.09a744588fab3
npm@8.1.2
8.11.0
1
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
npm@8.1.2
8.11.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
npm@8.5.5
8.11.0
1
hugohg34/server:0.0.2503e5d8960ff
npm@8.5.5
8.11.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
npm@8.1.0
8.11.0
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
npm@8.1.0
8.11.0
1
jakowenko/double-take:1.6.0b858bac9e32a
npm@8.1.0
8.11.0
1
jesec/flood:4.7.03d1d0bec117a
npm@7.24.0
8.11.0
1
jesec/flood:4.6.060bd59cfb4eb
npm@7.13.0
8.11.0
1
jesec/rtorrent-flood:latestf0c894ec459e
npm@7.15.1
8.11.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
npm@9.2.0~ds1-2
no fix listed
1
keyoxide/keyoxide:stable96f27a71269d
npm@8.3.1
8.11.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
npm@8.5.5
8.11.0
1
library/node:16.13.0-alpine60ef0bed1dc2
npm@8.1.0
8.11.0
1
lissy93/dashy:2.0.51991f7be5ed0
npm@8.1.2
8.11.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
npm@8.5.5
8.11.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed
1
milesmcc/shynet:v0.13.1ba54f7797a6b
npm@7.17.0
8.11.0
1
milesmcc/shynet:v0.12.0e821e31140f7
npm@7.17.0
8.11.0
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
npm@8.1.3
8.11.0
1
misskey/misskey:12.110.1e08b7c478093
npm@8.3.1
8.11.0
1
nonkronk/tristian-id:latest0a3694d70647
npm@8.3.1
8.11.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
npm@8.3.1
8.11.0
1
openemr/openemr:6.1.089eaa6d9a4e3
npm@8.1.3
8.11.0
1
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
no fix listed
1
pawelmalak/flame:2.1.193e7b0abb603
npm@8.1.2
8.11.0
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
npm@8.1.0
8.11.0
1
plumdog/db-operator:latest0c2fa2db0357
npm@8.1.2
8.11.0
1
polonel/trudesk:1.2.60cf6513f6fe3
npm@8.5.0
8.11.0
1
punkerside/noroot:v0.0.7be20c81d6ca1
npm@8.10.0
8.11.0
1
samajh/alprbackend:latestea742b4372ad
npm@8.5.0
8.11.0
1
samajh/alprfrontend:latest05ef4fddbb75
npm@8.5.0
8.11.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.