CVE-2022-46146
MediumAdvisory
Published 29 Nov 2022In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.2
- base score, highest
- EPSS
- 0.012
- 66th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 56
- of 17,781 indexed, latest versions
- Container images
- 51
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Prometheus Exporter-Toolkit is vulnerable to authentication bypass
Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 51 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.5.1, v0.6.0, v0.6.1, v0.7.0+3 more | 0.7.2, 0.8.2 | 51 |
- OSV records
- GHSA-7rg2-cxvp-9p7p
- Also known as
- GO-2022-1130
Charts affected
56 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| devtron-enterpriseromholdings | 48.0.0 | 1 of 28See more | 68,240 |
| devtron-operatorromholdings | 0.23.3 | 1 of 11See more | 32,902 |
| kube-prometheus-stackromholdings | 19.3.0 | 2 of 6See more | 8,645 |
| alertmanagersignoz | 0.5.2 | 1 of 1See more | 2,181 |
| temporaltemporal | 0.28.9 | 3 of 13See more | 21,005 |
| monitoringthl-chartsVerified publisher | 0.1.1 | 5 of 10See more | 18,908 |
Container images carrying it
51 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | b37103e03399 | github.com/ | 0.7.2 | 1 |