StackRadar

CVE-2022-41720

Unscored

Advisory

Published 7 Dec 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,354
of 17,790 indexed, latest versions
Container images
1,485
deployed by those charts
Fix available
1 of 1
affected package

Restricted file access on Windows in os and net/http

Carried by container images the latest versions of 1,354 of 17,790 indexed charts deploy, on 1,485 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+85 more1.18.91,485
OSV records
GO-2022-1143
Also known as
BIT-golang-2022-41720

Charts affected

1,354 by stars
ChartLatestAffected imagesRadar Score
ethexporterethersphereVerified publisher0.3.01 of 1See more

ethexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
darkobas/ethexporter:latest62e6464491ba
stdlib@go1.19.1
1.18.9

Open the chart page →

2,394
ethproxyethersphereVerified publisher0.2.01 of 1See more

ethproxy ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ethersphere/ethproxy:latest3a8a3926caa2
stdlib@go1.18.7
1.18.9

Open the chart page →

1,400
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.186d6d12a40465
stdlib@go1.18.2
1.18.9

Open the chart page →

4,756
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.18.9

Open the chart page →

3,320
tokenexporterethersphereVerified publisher0.3.01 of 1See more

tokenexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
darkobas/tokenexporter:latesta0349a0eedf0
stdlib@go1.19.1
1.18.9

Open the chart page →

2,394
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
stdlib@go1.18.1
1.18.9

Open the chart page →

20,987
pgbouncerevilmartians0.2.01 of 2See more

pgbouncer evilmartians 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.18.9

Open the chart page →

1,838
exa-csiexa-csi-driver0.2.0-rev21 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

1 of the 6 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.18.9

Open the chart page →

7,050
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
stdlib@go1.17.1
1.18.9

Open the chart page →

7,665
degafactlyVerified publisher0.11.132 of 3See more

dega factly 0.11.13

2 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.18.9
factly/dega-server:0.15.194d21479382e
stdlib@go1.16.2
1.18.9

Open the chart page →

5,747
kavachfactlyVerified publisher0.9.51 of 2See more

kavach factly 0.9.5

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
factly/kavach-server:0.22.3be85ff1b9bd3
stdlib@go1.16.2
1.18.9

Open the chart page →

3,573
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
stdlib@go1.13
1.18.9

Open the chart page →

4,645
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
stdlib@go1.19.3
1.18.9

Open the chart page →

1,758
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
stdlib@go1.16.5
1.18.9

Open the chart page →

13,491
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
stdlib@go1.17.8
1.18.9

Open the chart page →

7,519
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
stdlib@go1.13.5
1.18.9

Open the chart page →

14,688
infrafibonacci-cluster-infraVerified publisher1.0.02 of 4See more

infra fibonacci-cluster-infra 1.0.0

2 of the 4 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.18.9
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.18.9

Open the chart page →

12,510
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
stdlib@go1.17.5
1.18.9

Open the chart page →

3,311
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
stdlib@go1.13
1.18.9

Open the chart page →

7,691
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.18.9

Open the chart page →

64,192
endpoint-auth-servicefiware0.1.43 of 4See more

endpoint-auth-service fiware 0.1.4

3 of the 4 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
stdlib@go1.18.3
1.18.9
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
stdlib@go1.18.5
1.18.9
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.18.9

Open the chart page →

11,834
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
stdlib@go1.15.5
1.18.9

Open the chart page →

3,365
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
stdlib@go1.17.9
1.18.9

Open the chart page →

2,808
mission-control-tenantflanksourceVerified publisher1.0.921 of 3See more

mission-control-tenant flanksource 1.0.92

1 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
stdlib@go1.17.13
1.18.9

Open the chart page →

5,684
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.18.9

Open the chart page →

4,079
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.18.9

Open the chart page →

8,046
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
stdlib@go1.16.6
1.18.9

Open the chart page →

2,630
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
stdlib@go1.15.1
1.18.9

Open the chart page →

2,245
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.18.9

Open the chart page →

1,408
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.18.2
1.18.9
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
stdlib@go1.17.8
1.18.9

Open the chart page →

6,610
aptlyg0dscookie0.4.01 of 2See more

aptly g0dscookie 0.4.0

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
stdlib@go1.18.3
1.18.9

Open the chart page →

3,481
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
stdlib@go1.18.1
1.18.9

Open the chart page →

4,428
passboltg0dscookie0.5.22 of 2See more

passbolt g0dscookie 0.5.2

2 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.18.9
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.18.9

Open the chart page →

7,983
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.18.9

Open the chart page →

2,401
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
stdlib@go1.19.1
1.18.9

Open the chart page →

1,219
galoygaloymoney0.34.71 of 24See more

galoy galoymoney 0.34.7

1 of the 24 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.18.9

Open the chart page →

8,679
galoygaloymoney20.34.71 of 24See more

galoy galoymoney2 0.34.7

1 of the 24 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
stdlib@go1.19.3
1.18.9

Open the chart page →

8,679
alertmanager-discordgeek-cookbookVerified publisher1.3.21 of 1See more

alertmanager-discord geek-cookbook 1.3.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.18.9

Open the chart page →

1,045
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
stdlib@go1.18.3
1.18.9

Open the chart page →

4,788
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
stdlib@go1.18.4
1.18.9

Open the chart page →

14,698
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
stdlib@go1.19.3
1.18.9

Open the chart page →

2,236
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.18.9

Open the chart page →

16,178
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
stdlib@go1.18.5
1.18.9

Open the chart page →

2,143
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.18.9

Open the chart page →

8,584
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
stdlib@go1.18.1
1.18.9

Open the chart page →

1,881
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
stdlib@go1.16.4
1.18.9

Open the chart page →

3,525
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
stdlib@go1.16
1.18.9

Open the chart page →

3,131
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.18.9

Open the chart page →

11,042
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
stdlib@go1.18.3
1.18.9

Open the chart page →

9,736
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.18.9

Open the chart page →

14,328

Container images carrying it

1,485 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.18.9
1
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.18.9
1
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.18.9
1
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.18.9
1
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.18.9
1
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.18.9
1
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.18.9
1
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.18.9
1
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.18.9
1
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.18.9
1
library/mongo:5.0.217c81758cb295
stdlib@go1.18.2
1.18.9
1
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.18.2
1.18.9
1
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.18.9
1
library/mongo:8.0.11dca8d11fe467
stdlib@go1.18.2
1.18.9
1
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.18.9
1
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.18.9
1
library/nats:2.9.6-alpine3.16f576cdc17cc3
stdlib@go1.19.3
1.18.9
1
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.18.9
1
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.18.9
1
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.18.9
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.18.9
1
library/postgres:16.4-alpine5660c2cbfea5
stdlib@go1.18.2
1.18.9
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.18.9
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.18.9
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.18.9
1
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.18.9
1
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.18.9
1
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.18.9
1
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.18.9
1
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.18.9
1
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.18.9
1
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.18.9
1
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.18.9
1
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.18.9
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
stdlib@go1.18.2
1.18.9
1
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.18.9
1
library/redis83edc2b8e9ff
stdlib@go1.18.2
1.18.9
1
library/redis:7.0.1092b8b307ee28
stdlib@go1.18.2
1.18.9
1
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.18.9
1
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.18.9
1
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.18.9
1
library/telegraf:1.20.428e98eece020
stdlib@go1.17.3
1.18.9
1
library/telegraf:1.19.0-alpine794079a7f241
stdlib@go1.16.5
1.18.9
1
library/telegraf:1.19-alpineaddb86c0c520
stdlib@go1.16.6
1.18.9
1
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.18.9
1
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.18.9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.