StackRadar

CVE-2022-42898

High

Advisory

Published 19 Nov 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.064
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,018
of 17,790 indexed, latest versions
Container images
1,029
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Enhancement Advisory: krb5 bug fix update

Carried by container images the latest versions of 1,018 of 17,790 indexed charts deploy, on 1,029 images.

Affected packageAffected versionsFixed inImages
krb5deb1.12+dfsg-2ubuntu5, 1.12+dfsg-2ubuntu5.1, 1.12+dfsg-2ubuntu5.3, 1.12+dfsg-2ubuntu5.4+17 more1.12+dfsg-2ubuntu5.4+esm3, 1.13.2+dfsg-5ubuntu2.2+esm3, 1.16-2ubuntu0.3, 1.17-3+deb10u5+3 more773
heimdaldeb1.6~git20131207+dfsg-1ubuntu1, 1.6~git20131207+dfsg-1ubuntu1.2, 1.7~git20150920+dfsg-4ubuntu1.16.04.1, 7.5.0+dfsg-1+5 more1.6~git20131207+dfsg-1ubuntu1.2+esm3, 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3, 7.5.0+dfsg-1ubuntu0.3, 7.7.0+dfsg-1ubuntu1.3274
krb5rpm1.15.1-37.el7_6, 1.15.1-37.el7_7.2, 1.15.1-46.el7, 1.15.1-50.el7+19 more0:1.15.1-55.el7_9, 0:1.18.2-25.el8_8, 0:1.19.1-24.el9_1, 1.16.3-150100.3.27.1+1 more179
krb5apk1.19.2-r4, 1.19.3-r01.19.4-r057
sambadeb2:4.3.11+dfsg-0ubuntu0.16.04.18, 2:4.7.6+dfsg~ubuntu-0ubuntu2.15, 2:4.13.17~dfsg-0ubuntu1.20.04.12:4.3.11+dfsg-0ubuntu0.16.04.34+esm2, 2:4.7.6+dfsg~ubuntu-0ubuntu2.29+esm1, 2:4.15.13+dfsg-0ubuntu0.20.04.14
OSV records
ALPINE-CVE-2022-42898RHEA-2023:3850RHSA-2022:8637RHSA-2022:8640UBUNTU-CVE-2022-42898DLA-3213-1DSA-5286-1openSUSE-SU-2024:12524-1SUSE-SU-2022:4155-1
Also known as
RHSA-2022:8638, RHSA-2022:8639, RHSA-2022:8641, RHSA-2022:8648, RHSA-2022:8662, USN-5800-1, USN-5822-1, USN-5822-2, USN-5828-1, USN-5936-1, USN-7582-1

Charts affected

1,018 by stars
ChartLatestAffected imagesRadar Score
wbaas-backupwbstack0.1.01 of 1See more

wbaas-backup wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
heimdal@7.5.0+dfsg-1
krb5@1.16-2ubuntu0.2
7.5.0+dfsg-1ubuntu0.3
1.16-2ubuntu0.3

Open the chart page →

9,748
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3

Open the chart page →

9,399
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
krb5@1.17-3+deb10u1
1.17-3+deb10u5

Open the chart page →

2,671
webapp-chartwebappchart1.0.01 of 1See more

webapp-chart webappchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
amagdi888/my-repo:hello-appd8a10fc8faf6
krb5@1.19.3-r0
1.19.4-r0

Open the chart page →

1,201
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
krb5@1.17-3
1.17-3+deb10u5

Open the chart page →

5,462
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
heimdal@7.7.0+dfsg-1ubuntu1
krb5@1.17-6ubuntu4.1
7.7.0+dfsg-1ubuntu1.3
1.17-6ubuntu4.2

Open the chart page →

14,420
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
heimdal@7.7.0+dfsg-1ubuntu1
krb5@1.17-6ubuntu4.1
7.7.0+dfsg-1ubuntu1.3
1.17-6ubuntu4.2
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
krb5@1.18.2-8.el8
0:1.18.2-25.el8_8

Open the chart page →

28,699
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3

Open the chart page →

7,552
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
heimdal@7.5.0+dfsg-1
krb5@1.16-2ubuntu0.1
7.5.0+dfsg-1ubuntu0.3
1.16-2ubuntu0.3

Open the chart page →

10,857
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
heimdal@7.7.0+dfsg-1ubuntu1
krb5@1.17-6ubuntu4.1
7.7.0+dfsg-1ubuntu1.3
1.17-6ubuntu4.2

Open the chart page →

15,287
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
krb5@1.18.2-5.el8
0:1.18.2-25.el8_8

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
krb5@1.18.2-14.el8
0:1.18.2-25.el8_8

Open the chart page →

6,138
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3

Open the chart page →

1,585
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3

Open the chart page →

2,021
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
krb5@1.18.2-14.el8
0:1.18.2-25.el8_8

Open the chart page →

11,592
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
krb5@1.18.2-22.el8_7
0:1.18.2-25.el8_8

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
krb5@1.18.2-22.el8_7
0:1.18.2-25.el8_8

Open the chart page →

3,697
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2022-42898.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
heimdal@7.5.0+dfsg-1
7.5.0+dfsg-1ubuntu0.3
yandex/clickhouse-server:21.3.204eccfffb01d7
heimdal@7.7.0+dfsg-1ubuntu1
7.7.0+dfsg-1ubuntu1.3

Open the chart page →

9,250

Container images carrying it

1,029 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u3
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
krb5@1.18.3-6+deb11u2
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/adresservice-nginx:latest849af80ab017
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/authorization-component-nginx:latest02d0644aa99b
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/bisc-frontend:latestd8a0334cddfc
krb5@1.17-3
1.17-3+deb10u5
1
ghcr.io/conductionnl/brpservice-nginx:latest4db9b77c4425
krb5@1.17-3+deb10u3
1.17-3+deb10u5
1
ghcr.io/conductionnl/contactcatalogus-nginx:latest480c84fa9e63
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/digispoof-interface-nginx:latest8fa4597217a4
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/eav-component-nginx:latestd785c893096c
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/eherkenning-ui-nginx:latestfcd2100d863f
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/grafregistratiecomponent-nginx:latestd0daf48dec68
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/instemmingservice-nginx:latesteeeb4e9f0485
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/landelijketabellencatalogus-nginx:lateste7076242888a
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/loggingcomponent-nginx:latestcee37e9cef09
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/logicservice-nginx:latest7c8ee08c591c
krb5@1.17-3+deb10u3
1.17-3+deb10u5
1
ghcr.io/conductionnl/medewerkercatalogus-nginx:latest06c3b27462e6
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/memo-component-nginx:latestfd28182f7ecf
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/notification-component-nginx:latestd53bda41ee3b
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/ocatiecatalogus-nginx:latestc46374fc8f32
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/orderregistratiecomponent-nginx:latest42acee4ab31c
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/procestypecatalogus-nginx:latestca6fc575a3ba
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/productenendienstencatalogus-nginx:latest4095e7207822
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/proto-component-commonground-nginx:latest5b1384e29b7d
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/review-component-nginx:latest5df5f92870a5
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/skeleton-pip:devce1ebe9387a2
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/taalhuizen-service-nginx:latest0bbaa7487c63
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/trouw-service-nginx:latest86fe293b99a2
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/user-component-nginx:latestb721579df8c3
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/verhuis-service-nginx:latest4473ce50435e
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/verzoekconversieservice-nginx:latestf449b82ce9d6
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/verzoekregistratiecomponent-nginx:lateste0c5f8a95098
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/verzoektypecatalogus-nginx:latest42c75ea8082c
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/waardepapieren-balie-nginx:latest2eb073ab8b83
krb5@1.17-3+deb10u1
1.17-3+deb10u5
1
ghcr.io/conductionnl/waardepapieren-nginx:latestaf31cf6cd59f
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/conductionnl/waardepapieren-register-nginx:latest3fba727a3cc1
krb5@1.17-3+deb10u2
1.17-3+deb10u5
1
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
krb5@1.18.2-14.el8
0:1.18.2-25.el8_8
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
krb5@1.18.2-8.el8
0:1.18.2-25.el8_8
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
krb5@1.18.2-8.el8
0:1.18.2-25.el8_8
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
krb5@1.18.2-8.el8
0:1.18.2-25.el8_8
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
krb5@1.18.2-8.el8
0:1.18.2-25.el8_8
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
krb5@1.18.2-8.el8
0:1.18.2-25.el8_8
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
heimdal@7.7.0+dfsg-1ubuntu1
krb5@1.17-6ubuntu4.1
7.7.0+dfsg-1ubuntu1.3
1.17-6ubuntu4.2
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
krb5@1.19.3-r0
1.19.4-r0
1
ghcr.io/dodevops/azure-app-exporter/azure-app-exporter:0.1.38b472877847f5
krb5@1.18.3-6+deb11u1
1.18.3-6+deb11u3
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
krb5@1.19.1-23.el9_1
0:1.19.1-24.el9_1
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
krb5@1.19.1-23.el9_1
0:1.19.1-24.el9_1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.