StackRadar

CVE-2022-3715

High

Advisory

Published 5 Jan 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
134
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: bash security update

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 134 images.

Affected packageAffected versionsFixed inImages
bashdeb5.1-6ubuntu15.1-6ubuntu1.1116
bashrpm5.1.8-5.el90:5.1.8-6.el9_118
OSV records
UBUNTU-CVE-2022-3715RHSA-2023:0340
Also known as
USN-6697-1

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

9,005
p4p40.1.02 of 7See more

p4 p4 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
mastercloudapps/planner:v1.2340a950b311b2
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

27,537
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

7,576
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

27,558
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

12,949
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

4,928
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

16,101
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

8,033
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
typesense/typesense:0.25.1035ccfbc3fd8
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

4,070
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

5,456
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

4,332
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

4,332
amt-configuresmarthallVerified publisher0.1.11 of 1See more

amt-configure smarthall 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
boxcutter/meshcmd:1.1.384e13f01bcab
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

2,720
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

13,079
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

13,767
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

12,048
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

5,841
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

12,048
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
xeladock/nginx2:latestc259a67b1dff
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

17,461
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

5,604
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

20,270
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

9,347
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

13,459
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

6,232
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
openebs/node-disk-operator:2.1.06afe2123c457
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

10,489
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2022-3715.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
bash@5.1-6ubuntu1
5.1-6ubuntu1.1

Open the chart page →

9,248

Container images carrying it

134 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
bash@5.1.8-5.el9
0:5.1.8-6.el9_1
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
bash@5.1-6ubuntu1
5.1-6ubuntu1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.