CVE-2022-41404
HighAdvisory
Published 12 Oct 2022In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.014
- 71st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 19
- of 17,781 indexed, latest versions
- Container images
- 19
- deployed by those charts
- Fix available
- None
- affected package
org.ini4j allows attackers to cause a Denial of Service (DoS)
Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 19 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| ini4jmaven | 0.5.2, 0.5.4 | no fix listed | 19 |
- OSV records
- GHSA-jr6h-r7vg-f9mc
Charts affected
19 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| druiddruid-helmVerified publisher | 37.0.2 | 1 of 3See more | 3,812 |
| minecraft-proxyminecraft-server-chartsVerified publisher | 3.10.0 | 1 of 1See more | 3,074 |
| puppetserverpuppetserver | 9.5.2 | 2 of 5See more | 14,184 |
| druidwiremindVerified publisher | 1.22.1 | 1 of 3See more | 7,930 |
| hivebigdata-chartsVerified publisher | 0.1.8 | 1 of 1See more | 7,166 |
| oesopsmxVerified publisher | 4.0.32 | 1 of 25See more | 107,811 |
| aerospike-graphaerospike-helmOfficialVerified publisher | 3.7.0 | 1 of 1See more | 322 |
| kokukokuVerified publisher | 1.0.0 | 1 of 7See more | 12,019 |
| starwhalestarwhaleVerified publisher | 0.6.15 | 1 of 4See more | 13,486 |
| graphserviceaerospike-helmVerified publisher | 3.3.0 | 1 of 1See more | 453 |
| puppetservercamptocamp3 | 1.0.1 | 1 of 2See more | 5,886 |
| hbasehbase | 0.1.7 | 1 of 4See more | 10,540 |
| druidhelmforgeVerified publisher | 1.3.6 | 1 of 4See more | 8,541 |
| minecrafthelmforgeVerified publisher | 1.5.3 | 1 of 1See more | 4,639 |
| my-bloody-jenkinsodavid | 0.1.218 | 1 of 1See more | 5,826 |
| hive-metastoreolehrgfVerified publisher | 0.1.0 | 1 of 1See more | 8,540 |
| minecraftpaul1365972-mc | 3.0.1 | 1 of 1See more | 4,253 |
| game-serverpvillaverdeVerified publisher | 1.0.5 | 1 of 1See more | 4,253 |
| hadoop-deploymenttejaswita-hadoop-helmchart | 1.0.0 | 1 of 1See more | 4,240 |
Container images carrying it
19 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apache/ | 0116fb802786 | ini4j | no fix listed | 2 |
| 5200710/ | e34ab066d2ed | ini4j | no fix listed | 1 |
| aerospike/ | 781ba5213efd | ini4j | no fix listed | 1 |
| aerospike/ | f35739b97a46 | ini4j | no fix listed | 1 |
| apache/ | 0cef139b6bf1 | ini4j | no fix listed | 1 |
| apache/ | af361b20bec0 | ini4j | no fix listed | 1 |
| itzg/ | 1c59f9631f3b | ini4j | no fix listed | 1 |
| itzg/ | 4e29d14082d9 | ini4j | no fix listed | 1 |
| itzg/ | 8672e335dbef | ini4j | no fix listed | 1 |
| odavid/ | e7ab3bbc948e | ini4j | no fix listed | 1 |
| ghcr.io/ | ac62269785ac | ini4j | no fix listed | 1 |
| ghcr.io/ | c1a267d9ed6d | ini4j | no fix listed | 1 |
| ghcr.io/ | e949b0f733f0 | ini4j | no fix listed | 1 |
| ghcr.io/ | 8368359c8dd0 | ini4j | no fix listed | 1 |
| ghcr.io/ | a56dfe91f5b1 | ini4j | no fix listed | 1 |
| ghcr.io/ | 916746209ac5 | ini4j | no fix listed | 1 |
| ghcr.io/ | 63873f3f698e | ini4j | no fix listed | 1 |
| public.ecr.aws/ | 794b3bff9510 | ini4j | no fix listed | 1 |
| quay.io/ | 58bd0bcf72f9 | ini4j | no fix listed | 1 |