StackRadar

CVE-2022-48174

Critical

Advisory

Published 22 Aug 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
106
of 17,781 indexed, latest versions
Container images
88
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 106 of 17,781 indexed charts deploy, on 88 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.36.0-r9, 1.36.1-r01.36.1-r173
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+2 more1:1.21.0-1ubuntu1.4+esm1, 1:1.30.1-4ubuntu6.5, 1:1.30.1-7ubuntu3.1, 1:1.35.0-4+deb12u115
OSV records
ALPINE-CVE-2022-48174DEBIAN-CVE-2022-48174UBUNTU-CVE-2022-48174
Also known as
USN-6335-1, USN-6961-1

Charts affected

106 by stars
ChartLatestAffected imagesRadar Score
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2022-48174.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
busybox@1.36.1-r0
1.36.1-r1
temporalio/server:1.22.0ddeebf8bad8f
busybox@1.36.1-r0
1.36.1-r1
temporalio/ui:2.16.2af9c9349708f
busybox@1.36.1-r0
1.36.1-r1

Open the chart page →

21,005
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-48174.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
1:1.35.0-4+deb12u1

Open the chart page →

10,086
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2022-48174.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
busybox@1.36.1-r0
1.36.1-r1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
busybox@1.36.1-r0
1.36.1-r1

Open the chart page →

4,815
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2022-48174.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.14.08c28b75bc416
busybox@1.36.1-r0
1.36.1-r1

Open the chart page →

17,323
wiremind-baremetalwiremindVerified publisher2.0.21 of 1See more

wiremind-baremetal wiremind 2.0.2

1 of the 1 container images this version deploys carry CVE-2022-48174.

Container imageDigestPackageFixed in
library/alpine:3.18.002bb6f428431
busybox@1.36.0-r9
1.36.1-r1

Open the chart page →

487
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-48174.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r1

Open the chart page →

3,480

Container images carrying it

88 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/nats:2.9.20-alpined6c6ae7df4a0
busybox@1.36.1-r0
1.36.1-r1
1
library/nextcloud:31.0.6-apache588609d76b21
busybox@1:1.35.0-4+b4
1:1.35.0-4+deb12u1
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
busybox@1.36.1-r0
1.36.1-r1
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
busybox@1.36.0-r9
1.36.1-r1
1
natsio/nats-server-config-reloader:0.14.08c28b75bc416
busybox@1.36.1-r0
1.36.1-r1
1
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
busybox@1.36.1-r0
1.36.1-r1
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
busybox@1:1.35.0-4+b3
1:1.35.0-4+deb12u1
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
busybox@1:1.35.0-4+b3
1:1.35.0-4+deb12u1
1
opsmx11/issuegen:v2.1.05c50ca123d88
busybox@1:1.21.0-1ubuntu1
1:1.21.0-1ubuntu1.4+esm1
1
phntom/chartmuseum:v0.16.053883b65d9b7
busybox@1.36.1-r0
1.36.1-r1
1
phsmith/rundeck-exporter:2.6.10265a7616ae8
busybox@1.36.0-r9
1.36.1-r1
1
pinclr/v2ray-proxy:latestf37f250b7091
busybox@1.36.0-r9
1.36.1-r1
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
busybox@1.36.1-r0
1.36.1-r1
1
rclone/rclone:1.63.008e1af3c8814
busybox@1.36.1-r0
1.36.1-r1
1
resouer/redis-slave:v2e2f198b49ba7
busybox@1:1.21.0-1ubuntu1
1:1.21.0-1ubuntu1.4+esm1
1
semitechnologies/weaviate:1.19.17a00d226f063
busybox@1.36.0-r9
1.36.1-r1
1
su541/cert-manager-desec-webhook:latest371ee33f83c1
busybox@1.36.1-r0
1.36.1-r1
1
temporalio/admin-tools:1.22.0836af062af30
busybox@1.36.1-r0
1.36.1-r1
1
temporalio/server:1.22.0ddeebf8bad8f
busybox@1.36.1-r0
1.36.1-r1
1
udhos/forward:1.1.312e120d39fdb
busybox@1.36.0-r9
1.36.1-r1
1
voltha/voltha-envoy:1.6.059ab2a00f712
busybox@1:1.21.0-1ubuntu1
1:1.21.0-1ubuntu1.4+esm1
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
busybox@1.36.0-r9
1.36.1-r1
1
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/cosmo-workspace/cosmo-traefik-plugins:v0.9.1435518f49e23
busybox@1.36.0-r9
1.36.1-r1
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/data-fair/metrics:0a8d40779eeae
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
busybox@1.36.1-r0
1.36.1-r1
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
busybox@1:1.30.1-4ubuntu6.4
1:1.30.1-4ubuntu6.5
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
busybox@1.36.0-r9
1.36.1-r1
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
busybox@1.36.0-r9
1.36.1-r1
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
busybox@1.36.0-r9
1.36.1-r1
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
busybox@1.36.1-r0
1.36.1-r1
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
busybox@1.36.0-r9
1.36.1-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.