StackRadar

CVE-2022-36227

Critical

Advisory

Published 22 Nov 2022In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.024
83rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
139
of 17,781 indexed, latest versions
Container images
160
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libarchive security update

Carried by container images the latest versions of 139 of 17,781 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
libarchivedeb3.1.2-11ubuntu0.16.04.3, 3.3.3-4+deb10u1, 3.4.0-2ubuntu1, 3.4.0-2ubuntu1.2+1 more3.1.2-11ubuntu0.16.04.8+esm1, 3.3.3-4+deb10u3, 3.4.0-2ubuntu1.3, 3.6.0-1ubuntu1.219
libarchiveapk3.6.0-r0, 3.6.1-r03.6.1-r12
libarchiverpm3.3.2-3.el8, 3.3.2-8.el8_1, 3.3.2-9.el8, 3.3.3-1.el8+4 more0:3.3.3-5.el8, 0:3.5.3-4.el9139
OSV records
ALPINE-CVE-2022-36227UBUNTU-CVE-2022-36227RHSA-2023:2532RHSA-2023:3018RLSA-2023:3018DLA-3294-1
Also known as
RHSA-2024:0146, USN-7070-1

Charts affected

139 by stars
ChartLatestAffected imagesRadar Score
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

18,023
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

7,459
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.64 of 6See more

fsm openshift 0.1.8-ubi.6

4 of the 6 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

16,556
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
libarchive@3.3.3-1.el8
0:3.3.3-5.el8
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi86 of 7See more

osm-edge openshift 1.2.1-ubi8

6 of the 7 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

19,455
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

5,554
p4p40.1.02 of 7See more

p4 p4 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
mastercloudapps/server:v2.23f3d24dfe2686
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
mastercloudapps/weatherservice:v1.23de859d29c116
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

27,537
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

15,466
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

15,466
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
libarchive@3.3.2-8.el8_1
0:3.3.3-5.el8

Open the chart page →

11,151
Practica_4_helmpr04helm0.1.02 of 7See more

Practica_4_helm pr04helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
codeurjc/weatherservice:v1.0b9e2f7234349
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

27,558
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

6,668
ibm-mongodb-enterprise-helmredhat0.3.01 of 1See more

ibm-mongodb-enterprise-helm redhat 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
libarchive@3.3.2-9.el8
0:3.3.3-5.el8

Open the chart page →

12,248
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
libarchive@3.3.2-8.el8_1
0:3.3.3-5.el8

Open the chart page →

11,437
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libarchive@3.3.3-4.el8_6
0:3.3.3-5.el8

Open the chart page →

16,047
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

29,227
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

5,422
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

6,237
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

21,997
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

6,443
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

11,554
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

6,671
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

6,596
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.3

Open the chart page →

10,006
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

12,455
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

4,960
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.3

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.3

Open the chart page →

9,130
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

28,605
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libarchive@3.3.2-9.el8
0:3.3.3-5.el8

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libarchive@3.3.3-1.el8
0:3.3.3-5.el8

Open the chart page →

6,138
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-36227.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libarchive@3.3.3-4.el8
0:3.3.3-5.el8

Open the chart page →

3,697

Container images carrying it

160 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/openshift/origin-cli:4.66722d5041b47
libarchive@3.3.2-8.el8_1
0:3.3.3-5.el8
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libarchive@3.3.2-8.el8_1
0:3.3.3-5.el8
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
libarchive@3.3.3-4.el8_6
0:3.3.3-5.el8
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
libarchive@3.3.3-1.el8
0:3.3.3-5.el8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
libarchive@3.3.3-1.el8
0:3.3.3-5.el8
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
libarchive@3.3.3-4.el8
0:3.3.3-5.el8
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
libarchive@3.3.3-1.el8
0:3.3.3-5.el8
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
libarchive@3.3.3-1.el8
0:3.3.3-5.el8
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libarchive@3.4.0-2ubuntu1
3.4.0-2ubuntu1.3
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
libarchive@3.3.3-3.el8_5
0:3.3.3-5.el8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.