StackRadar

CVE-2022-4304

Medium

Advisory

Published 7 Feb 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.162
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,060
of 17,787 indexed, latest versions
Container images
1,063
deployed by those charts
Fix available
3 of 4
affected packages

Security update for openssl-1_1

Carried by container images the latest versions of 1,060 of 17,787 indexed charts deploy, on 1,063 images.

Affected packageAffected versionsFixed inImages
opensslapk1.1.1k-r0, 1.1.1l-r0, 1.1.1l-r7, 1.1.1l-r8+9 more1.1.1t-r0, 3.0.8-r0566
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+55 more1.1.1-1ubuntu2.1~18.04.21, 1.1.1-1ubuntu2.fips.2.1~18.04.21, 1.1.1f-1ubuntu2.17, 1.1.1f-1ubuntu2.fips.17+1 more490
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 moreno fix listed15
openssl-1_1rpm1.1.0i-14.6.11.1.0i-150100.14.56.17
OSV records
ALPINE-CVE-2022-4304UBUNTU-CVE-2022-4304SUSE-SU-2023:2622-1
Also known as
USN-5844-1

Charts affected

1,060 by stars
ChartLatestAffected imagesRadar Score
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
openssl@1.1.1l-r7
1.1.1t-r0

Open the chart page →

2,616
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
openssl@1.1.1n-r0
1.1.1t-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
openssl@1.1.1n-r0
1.1.1t-r0

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
openssl@1.1.1l-r0
1.1.1t-r0

Open the chart page →

2,535
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
openssl@1.1.1n-r0
1.1.1t-r0

Open the chart page →

1,752
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
openssl@1.1.1q-r0
1.1.1t-r0

Open the chart page →

1,152
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
openssl@1.1.1n-r0
1.1.1t-r0

Open the chart page →

7,972
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.fips.2.1~18.04.21

Open the chart page →

2,464
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.8-r0

Open the chart page →

5,847
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
openssl@1.1.1l-r7
1.1.1t-r0

Open the chart page →

3,118
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.21
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.17

Open the chart page →

9,250

Container images carrying it

1,063 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
zeetdev/tailscale-relay:v1.24.21967aa2840b6
openssl@1.1.1n-r0
1.1.1t-r0
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
openssl@1.1.1l-r7
1.1.1t-r0
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
openssl@1.1.1-1ubuntu2.1~18.04.5
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.21
no fix listed
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
openssl@1.0.2g-1ubuntu4.8
no fix listed
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
openssl@1.0.2g-1ubuntu4.8
no fix listed
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
openssl@1.0.2g-1ubuntu4.15
no fix listed
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.17
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
openssl@1.0.2g-1ubuntu4.15
no fix listed
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.17
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
openssl@1.1.1k-r0
1.1.1t-r0
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
openssl@1.1.1k-r0
1.1.1t-r0
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
openssl@1.0.2g-1ubuntu4.20
no fix listed
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.fips.17
1
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.fips.2.1~18.04.21
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
openssl@1.1.1l-r0
1.1.1t-r0
1
ghcr.io/alexanderbabel/database-s3-backup:1.3.33191b771a6f2
openssl@1.1.1l-r0
1.1.1t-r0
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/arpa-network/node-shell:latest6b359ace1408
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/bakito/sealed-secrets-web:v3.0.574aff24d4b97
openssl@3.0.7-r0
3.0.8-r0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.fips.17
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/ckotzbauer/chekrf299baf467b5
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
openssl-1_1@1.1.0i-14.6.1
1.1.0i-150100.14.56.1
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
openssl-1_1@1.1.0i-14.6.1
1.1.0i-150100.14.56.1
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
openssl-1_1@1.1.0i-14.6.1
1.1.0i-150100.14.56.1
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
openssl-1_1@1.1.0i-14.6.1
1.1.0i-150100.14.56.1
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
openssl-1_1@1.1.0i-14.6.1
1.1.0i-150100.14.56.1
1
ghcr.io/clusterpedia-io/clusterpedia/apiserver:v0.6.03d089d9078f8
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/clusterpedia-io/clusterpedia/clustersynchro-manager:v0.6.082cc9a77f6d6
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/clusterpedia-io/clusterpedia/controller-manager:v0.6.081669df338e0
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/dask/dask:2024.1.0080150de7d86
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.fips.17
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.17
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
openssl@1.1.1n-r0
1.1.1t-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.