StackRadar

CVE-2021-22097

Medium

Advisory

Published 24 May 2022In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
23
deployed by those charts
Fix available
1 of 1
affected package

Deserialization of Untrusted Data in Spring AMQP

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 23 images.

Affected packageAffected versionsFixed inImages
spring-amqpmaven2.2.1.RELEASE, 2.2.5.RELEASE, 2.2.10.RELEASE, 2.2.11.RELEASE+4 more2.2.19, 2.3.1123
OSV records
GHSA-fx7f-rjqj-52pj

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
geoserver-cloudcamptocamp20.0.55 of 11See more

geoserver-cloud camptocamp2 0.0.5

5 of the 11 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-amqp@2.2.10.RELEASE
2.2.19

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.65 of 11See more

geoserverCloud camptocamp2 0.0.6

5 of the 11 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-amqp@2.2.10.RELEASE
2.2.19

Open the chart page →

84,444
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
torrespro/mca-worker:2.0.06d3bd305a1ba
spring-amqp@2.2.1.RELEASE
2.2.19

Open the chart page →

19,187
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
spring-amqp@2.2.1.RELEASE
2.2.19

Open the chart page →

19,745
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-amqp@2.2.10.RELEASE
2.2.19
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-amqp@2.2.10.RELEASE
2.2.19

Open the chart page →

88,335
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
amartinm82/planner:v2.01184353ff57b
spring-amqp@2.3.1
2.3.11

Open the chart page →

27,550
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
oscarsotosanchez/planner:v1.0730c00a099b8
spring-amqp@2.3.1
2.3.11

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
franrobles8/planner:v3.099985392d63c
spring-amqp@2.3.1
2.3.11

Open the chart page →

27,256
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
spring-amqp@2.3.10
2.3.11

Open the chart page →

7,691
lavandaluiscajl0.0.1343 of 5See more

lavanda luiscajl 0.0.134

3 of the 5 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-amqp@2.2.11.RELEASE
2.2.19
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-amqp@2.2.11.RELEASE
2.2.19
lavandadelpatio/tmdb:0.0.2f36af885e915
spring-amqp@2.3.6
2.3.11

Open the chart page →

18,248
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
spring-amqp@2.2.1.RELEASE
2.2.19

Open the chart page →

19,720
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
slagattollas/planner-practica:latestcecd95e31486
spring-amqp@2.3.1
2.3.11

Open the chart page →

28,484
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2021-22097.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
spring-amqp@2.2.5.RELEASE
2.2.19
reportportal/service-jobs:5.7.2dc166c58485a
spring-amqp@2.3.5
2.3.11

Open the chart page →

25,737

Container images carrying it

23 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-amqp@2.2.10.RELEASE
2.2.19
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-amqp@2.2.10.RELEASE
2.2.19
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-amqp@2.2.10.RELEASE
2.2.19
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-amqp@2.2.10.RELEASE
2.2.19
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-amqp@2.2.10.RELEASE
2.2.19
2
amartinm82/planner:v2.01184353ff57b
spring-amqp@2.3.1
2.3.11
1
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
spring-amqp@2.3.10
2.3.11
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
spring-amqp@2.2.1.RELEASE
2.2.19
1
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
spring-amqp@2.2.1.RELEASE
2.2.19
1
franrobles8/planner:v3.099985392d63c
spring-amqp@2.3.1
2.3.11
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-amqp@2.2.10.RELEASE
2.2.19
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-amqp@2.2.10.RELEASE
2.2.19
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-amqp@2.2.10.RELEASE
2.2.19
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-amqp@2.2.10.RELEASE
2.2.19
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-amqp@2.2.10.RELEASE
2.2.19
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-amqp@2.2.11.RELEASE
2.2.19
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-amqp@2.2.11.RELEASE
2.2.19
1
lavandadelpatio/tmdb:0.0.2f36af885e915
spring-amqp@2.3.6
2.3.11
1
oscarsotosanchez/planner:v1.0730c00a099b8
spring-amqp@2.3.1
2.3.11
1
reportportal/service-api:5.7.29df41f8fb320
spring-amqp@2.2.5.RELEASE
2.2.19
1
reportportal/service-jobs:5.7.2dc166c58485a
spring-amqp@2.3.5
2.3.11
1
slagattollas/planner-practica:latestcecd95e31486
spring-amqp@2.3.1
2.3.11
1
torrespro/mca-worker:2.0.06d3bd305a1ba
spring-amqp@2.2.1.RELEASE
2.2.19
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.