StackRadar

CVE-2022-4304

Medium

Advisory

Published 7 Feb 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.162
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,060
of 17,787 indexed, latest versions
Container images
1,063
deployed by those charts
Fix available
3 of 4
affected packages

Security update for openssl-1_1

Carried by container images the latest versions of 1,060 of 17,787 indexed charts deploy, on 1,063 images.

Affected packageAffected versionsFixed inImages
opensslapk1.1.1k-r0, 1.1.1l-r0, 1.1.1l-r7, 1.1.1l-r8+9 more1.1.1t-r0, 3.0.8-r0566
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+55 more1.1.1-1ubuntu2.1~18.04.21, 1.1.1-1ubuntu2.fips.2.1~18.04.21, 1.1.1f-1ubuntu2.17, 1.1.1f-1ubuntu2.fips.17+1 more490
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 moreno fix listed15
openssl-1_1rpm1.1.0i-14.6.11.1.0i-150100.14.56.17
OSV records
ALPINE-CVE-2022-4304UBUNTU-CVE-2022-4304SUSE-SU-2023:2622-1
Also known as
USN-5844-1

Charts affected

1,060 by stars
ChartLatestAffected imagesRadar Score
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
openssl@1.1.1l-r7
1.1.1t-r0

Open the chart page →

2,616
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
openssl@1.1.1n-r0
1.1.1t-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
openssl@1.1.1n-r0
1.1.1t-r0

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
openssl@1.1.1l-r0
1.1.1t-r0

Open the chart page →

2,535
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
openssl@1.1.1n-r0
1.1.1t-r0

Open the chart page →

1,752
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
openssl@1.1.1q-r0
1.1.1t-r0

Open the chart page →

1,152
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
openssl@1.1.1n-r0
1.1.1t-r0

Open the chart page →

7,972
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.fips.2.1~18.04.21

Open the chart page →

2,464
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.8-r0

Open the chart page →

5,847
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
openssl@1.1.1l-r7
1.1.1t-r0

Open the chart page →

3,118
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2022-4304.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.21
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.17

Open the chart page →

9,250

Container images carrying it

1,063 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/devplayer0/dnsmasq:0.1.1dd7b949b504a
openssl@1.1.1k-r0
1.1.1t-r0
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
openssl@1.1.1l-r0
1.1.1t-r0
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
openssl@1.1.1k-r0
1.1.1t-r0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.21
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
openssl@1.1.1n-r0
1.1.1t-r0
1
ghcr.io/douban/aliyun-exporter:mainb7c694331362
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/douban/qiniu-exporter:maind1da3bcfad7d
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/douban/ucloud-exporter:mainb4bb8a9021a2
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/douban/upyun-exporter:main6810900c9c4a
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
openssl@1.1.1-1ubuntu2.1~18.04.13
1.1.1-1ubuntu2.1~18.04.21
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.17
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.17
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
openssl@1.1.1o-r0
1.1.1t-r0
1
ghcr.io/hadron-project/hadron/hadron-operator:v0.1.0-beta.10244335958e0
openssl@1.1.1l-r0
1.1.1t-r0
1
ghcr.io/hascheksolutions/pictshare:19d7cb06987f95505e9f
openssl@1.1.1l-r0
1.1.1t-r0
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.17
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
openssl@1.1.1l-r7
1.1.1t-r0
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
openssl@1.1.1o-r0
1.1.1t-r0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
openssl@1.1.1l-r0
1.1.1t-r0
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.fips.2.1~18.04.21
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.17
1
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/k10app/businit:latest94c9a3e799c2
openssl@3.0.7-r0
3.0.8-r0
1
ghcr.io/k10app/catalog:latest639c980be0f1
openssl@1.1.1s-r0
1.1.1t-r0
1
ghcr.io/k10app/order:lateste1017d0dbd78
openssl@3.0.7-r0
3.0.8-r0
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
openssl@1.1.1f-1ubuntu2.5
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.8
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/pod-gateway:v1.6.1dcb2d814a4f7
openssl@1.1.1q-r0
1.1.1t-r0
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.8
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.8
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.17
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.17
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.