StackRadar

CVE-2022-41404

High

Advisory

Published 12 Oct 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
None
affected package

org.ini4j allows attackers to cause a Denial of Service (DoS)

Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
ini4jmaven0.5.2, 0.5.4no fix listed19
OSV records
GHSA-jr6h-r7vg-f9mc

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
ini4j@0.5.4
no fix listed

Open the chart page →

3,812
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
ini4j@0.5.4
no fix listed

Open the chart page →

3,074
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
ini4j@0.5.4
no fix listed
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
ini4j@0.5.4
no fix listed

Open the chart page →

14,184
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
ini4j@0.5.4
no fix listed

Open the chart page →

7,930
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
ini4j@0.5.4
no fix listed

Open the chart page →

7,166
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
ini4j@0.5.4
no fix listed

Open the chart page →

107,811
aerospike-graphaerospike-helmOfficialVerified publisher3.7.01 of 1See more

aerospike-graph aerospike-helm 3.7.0

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
aerospike/aerospike-graph-service:3.3.1781ba5213efd
ini4j@0.5.4
no fix listed

Open the chart page →

322
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
ini4j@0.5.4
no fix listed

Open the chart page →

12,019
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
ini4j@0.5.4
no fix listed

Open the chart page →

13,486
graphserviceaerospike-helmVerified publisher3.3.01 of 1See more

graphservice aerospike-helm 3.3.0

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
aerospike/aerospike-graph-service:3.3.0f35739b97a46
ini4j@0.5.4
no fix listed

Open the chart page →

453
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
ini4j@0.5.4
no fix listed

Open the chart page →

5,886
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
ini4j@0.5.4
no fix listed

Open the chart page →

10,540
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
ini4j@0.5.4
no fix listed

Open the chart page →

8,541
minecrafthelmforgeVerified publisher1.5.31 of 1See more

minecraft helmforge 1.5.3

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
itzg/minecraft-server:2026.9.04e29d14082d9
ini4j@0.5.4
no fix listed

Open the chart page →

4,639
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
ini4j@0.5.2
no fix listed

Open the chart page →

5,826
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
ini4j@0.5.4
no fix listed

Open the chart page →

8,540
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest8672e335dbef
ini4j@0.5.4
no fix listed

Open the chart page →

4,253
game-serverpvillaverdeVerified publisher1.0.51 of 1See more

game-server pvillaverde 1.0.5

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
ini4j@0.5.4
no fix listed

Open the chart page →

4,253
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41404.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
ini4j@0.5.4
no fix listed

Open the chart page →

4,240

Container images carrying it

19 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/druid:37.0.00116fb802786
ini4j@0.5.4
no fix listed
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
ini4j@0.5.4
no fix listed
1
aerospike/aerospike-graph-service:3.3.1781ba5213efd
ini4j@0.5.4
no fix listed
1
aerospike/aerospike-graph-service:3.3.0f35739b97a46
ini4j@0.5.4
no fix listed
1
apache/druid:29.0.10cef139b6bf1
ini4j@0.5.4
no fix listed
1
apache/hadoop:3af361b20bec0
ini4j@0.5.4
no fix listed
1
itzg/bungeecord:latest1c59f9631f3b
ini4j@0.5.4
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
ini4j@0.5.4
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
ini4j@0.5.4
no fix listed
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
ini4j@0.5.2
no fix listed
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
ini4j@0.5.4
no fix listed
1
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
ini4j@0.5.4
no fix listed
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
ini4j@0.5.4
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
ini4j@0.5.4
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
ini4j@0.5.4
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
ini4j@0.5.4
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
ini4j@0.5.4
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
ini4j@0.5.4
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
ini4j@0.5.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.