StackRadar

CVE-2022-41720

Unscored

Advisory

Published 7 Dec 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,354
of 17,787 indexed, latest versions
Container images
1,485
deployed by those charts
Fix available
1 of 1
affected package

Restricted file access on Windows in os and net/http

Carried by container images the latest versions of 1,354 of 17,787 indexed charts deploy, on 1,485 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+85 more1.18.91,485
OSV records
GO-2022-1143
Also known as
BIT-golang-2022-41720

Charts affected

1,354 by stars
ChartLatestAffected imagesRadar Score
fission-corefission-chartsVerified publisher1.14.13 of 3See more

fission-core fission-charts 1.14.1

3 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
stdlib@go1.15.14
1.18.9
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
stdlib@go1.15.14
1.18.9
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.18.9

Open the chart page →

7,104
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.18.9

Open the chart page →

3,313
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.18.9

Open the chart page →

3,391
gboxgboxVerified publisher1.0.51 of 2See more

gbox gbox 1.0.5

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
gboxproxy/gbox:v1.0.63a9f4a711d5c
stdlib@go1.17.9
1.18.9

Open the chart page →

2,521
adguard-homegeek-cookbookVerified publisher5.5.21 of 2See more

adguard-home geek-cookbook 5.5.2

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.7b9974aed13d0
stdlib@go1.17.9
1.18.9

Open the chart page →

1,742
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
stdlib@go1.13.15
1.18.9

Open the chart page →

3,586
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.18.9

Open the chart page →

17,438
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
stdlib@go1.16.9
1.18.9

Open the chart page →

3,474
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
stdlib@go1.16.5
1.18.9

Open the chart page →

3,631
influxdb-exportergeek-cookbookVerified publisher1.2.21 of 1See more

influxdb-exporter geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.18.9

Open the chart page →

1,051
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
stdlib@go1.17.7
1.18.9

Open the chart page →

2,556
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
stdlib@go1.15.2
1.18.9

Open the chart page →

3,167
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
stdlib@go1.15.12
1.18.9

Open the chart page →

8,035
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.18.9

Open the chart page →

11,606
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.18.9

Open the chart page →

10,279
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.18.9

Open the chart page →

2,318
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.18.9

Open the chart page →

13,071
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.18.9

Open the chart page →

15,917
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
stdlib@go1.17.5
1.18.9

Open the chart page →

5,079
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.18.9

Open the chart page →

7,698
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.18.9

Open the chart page →

15,606
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.18.9

Open the chart page →

6,458
carettagroundcover0.0.162 of 3See more

caretta groundcover 0.0.16

2 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
stdlib@go1.18
1.18.9
quay.io/groundcover/grafana:9.3.18c65b333a3d3
stdlib@go1.19.3
1.18.9

Open the chart page →

6,799
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
stdlib@go1.17.9
1.18.9
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.18.9

Open the chart page →

13,656
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.18.9

Open the chart page →

8,773
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.18.9

Open the chart page →

6,977
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.18.9

Open the chart page →

2,913
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.18.9

Open the chart page →

6,810
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
stdlib@go1.17.2
1.18.9

Open the chart page →

1,573
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.18.9

Open the chart page →

15,749
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
stdlib@go1.17.1
1.18.9

Open the chart page →

2,167
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
stdlib@go1.16.6
1.18.9

Open the chart page →

10,415
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.18.9

Open the chart page →

10,489
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.18.9

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.18.9

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.18.9

Open the chart page →

10,716
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.18.9

Open the chart page →

1,812
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
stdlib@go1.17.13
1.18.9

Open the chart page →

9,318
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
stdlib@go1.18.7
1.18.9

Open the chart page →

3,369
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.18.9

Open the chart page →

5,302
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
stdlib@go1.14.8
1.18.9
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.18.9

Open the chart page →

5,408
kubefedkubefed0.10.01 of 2See more

kubefed kubefed 0.10.0

1 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
stdlib@go1.16.6
1.18.9

Open the chart page →

2,419
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
stdlib@go1.18.7
1.18.9

Open the chart page →

3,275
mesherykubesphere-stable0.5.02 of 13See more

meshery kubesphere-stable 0.5.0

2 of the 13 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
stdlib@go1.13.1
1.18.9
layer5/meshery-nsm:stable-latestebd6a8faf21f
stdlib@go1.15.12
1.18.9

Open the chart page →

24,690
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.18.9

Open the chart page →

2,605
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.18.9

Open the chart page →

1,575
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
stdlib@go1.18
1.18.9
kubemod/kubemod-crt:v1.3.0028347c9fa77
stdlib@go1.18.1
1.18.9

Open the chart page →

4,542
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.21 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

1 of the 5 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
stdlib@go1.18.5
1.18.9

Open the chart page →

6,872
kube-fencingkvaps2.4.12 of 2See more

kube-fencing kvaps 2.4.1

2 of the 2 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
stdlib@go1.18.8
1.18.9
ghcr.io/kvaps/kube-fencing-switcher:v2.4.0f8c378e63b78
stdlib@go1.18.8
1.18.9

Open the chart page →

2,538
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2022-41720.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
stdlib@go1.15.14
1.18.9
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
stdlib@go1.15.14
1.18.9
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
stdlib@go1.15.14
1.18.9
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
stdlib@go1.15.14
1.18.9

Open the chart page →

15,551

Container images carrying it

1,485 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.18.9
1
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.18.9
1
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.18.9
1
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.18.9
1
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.18.9
1
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.18.9
1
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.18.9
1
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.18.9
1
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.18.9
1
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.18.9
1
library/mongo:5.0.217c81758cb295
stdlib@go1.18.2
1.18.9
1
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.18.2
1.18.9
1
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.18.9
1
library/mongo:8.0.11dca8d11fe467
stdlib@go1.18.2
1.18.9
1
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.18.9
1
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.18.9
1
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.18.9
1
library/nats:2.9.6-alpine3.16f576cdc17cc3
stdlib@go1.19.3
1.18.9
1
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.18.9
1
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.18.9
1
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.18.9
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.18.9
1
library/postgres:16.4-alpine5660c2cbfea5
stdlib@go1.18.2
1.18.9
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.18.9
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.18.9
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.18.9
1
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.18.9
1
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.18.9
1
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.18.9
1
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.18.9
1
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.18.9
1
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.18.9
1
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.18.9
1
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.18.9
1
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.18.9
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
stdlib@go1.18.2
1.18.9
1
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.18.9
1
library/redis83edc2b8e9ff
stdlib@go1.18.2
1.18.9
1
library/redis:7.0.1092b8b307ee28
stdlib@go1.18.2
1.18.9
1
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.18.9
1
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.18.9
1
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.18.9
1
library/telegraf:1.20.428e98eece020
stdlib@go1.17.3
1.18.9
1
library/telegraf:1.19.0-alpine794079a7f241
stdlib@go1.16.5
1.18.9
1
library/telegraf:1.19-alpineaddb86c0c520
stdlib@go1.16.6
1.18.9
1
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.18.9
1
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.18.9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.