StackRadar

CVE-2021-22573

High

Advisory

Published 9 Apr 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
26
deployed by those charts
Fix available
1 of 1
affected package

google-oauth-java-client improperly verifies cryptographic signature

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 26 images.

Affected packageAffected versionsFixed inImages
google-oauth-clientmaven1.17.0-rc, 1.19.0, 1.20.0, 1.22.0+8 more1.33.326
OSV records
GHSA-hw42-3568-wj87

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
google-oauth-client@1.26.0
1.33.3

Open the chart page →

10,469
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
google-oauth-client@1.26.0
1.33.3

Open the chart page →

11,839
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
google-oauth-client@1.31.5
1.33.3

Open the chart page →

107,811
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
google-oauth-client@1.22.0
1.33.3

Open the chart page →

7,891
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
google-oauth-client@1.30.2
1.33.3

Open the chart page →

8,752
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
google-oauth-client@1.31.5
1.33.3

Open the chart page →

5,291
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
google-oauth-client@1.32.1
1.33.3

Open the chart page →

24,930
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
google-oauth-client@1.32.1
1.33.3

Open the chart page →

1,413
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
google-oauth-client@1.23.0
1.33.3

Open the chart page →

5,489
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
google-oauth-client@1.19.0
1.33.3

Open the chart page →

4,906
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
google-oauth-client@1.26.0
1.33.3

Open the chart page →

22,442
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
google-oauth-client@1.31.1
1.33.3
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
google-oauth-client@1.31.1
1.33.3
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
google-oauth-client@1.31.1
1.33.3
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
google-oauth-client@1.31.1
1.33.3
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
google-oauth-client@1.31.1
1.33.3
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
google-oauth-client@1.31.1
1.33.3

Open the chart page →

58,857
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
google-oauth-client@1.20.0
1.33.3

Open the chart page →

27,949
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
google-oauth-client@1.31.0
1.33.3

Open the chart page →

6,102
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
google-oauth-client@1.25.0
1.33.3

Open the chart page →

7,144
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
google-oauth-client@1.31.0
1.33.3

Open the chart page →

10,777
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
google-oauth-client@1.26.0
1.33.3

Open the chart page →

11,188
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
google-oauth-client@1.25.0
1.33.3

Open the chart page →

63,223
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
google-oauth-client@1.26.0
1.33.3

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
google-oauth-client@1.32.1
1.33.3

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
google-oauth-client@1.32.1
1.33.3

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
google-oauth-client@1.31.0
1.33.3

Open the chart page →

13,767
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2021-22573.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
google-oauth-client@1.17.0-rc
1.33.3

Open the chart page →

6,213

Container images carrying it

26 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
google-oauth-client@1.32.1
1.33.3
3
airbyte/cron:0.40.17caf4f551c546
google-oauth-client@1.32.1
1.33.3
1
apacheignite/ignite:2.7.0d7deab68b8fa
google-oauth-client@1.22.0
1.33.3
1
apachepinot/pinot:latest-jdk110018bb04ced7
google-oauth-client@1.31.0
1.33.3
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
google-oauth-client@1.31.1
1.33.3
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
google-oauth-client@1.31.1
1.33.3
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
google-oauth-client@1.31.1
1.33.3
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
google-oauth-client@1.31.1
1.33.3
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
google-oauth-client@1.31.1
1.33.3
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
google-oauth-client@1.31.1
1.33.3
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
google-oauth-client@1.31.0
1.33.3
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
google-oauth-client@1.31.5
1.33.3
1
jacobalberty/unifi:v7.1.664a3616625dda
google-oauth-client@1.26.0
1.33.3
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
google-oauth-client@1.26.0
1.33.3
1
jacobalberty/unifi:5.10.19c409924e2463
google-oauth-client@1.26.0
1.33.3
1
linuxserver/unifi-controller:8.0.240ae315a3a456
google-oauth-client@1.26.0
1.33.3
1
linuxserver/unifi-controller:7.3.83ab105cc50322
google-oauth-client@1.26.0
1.33.3
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
google-oauth-client@1.17.0-rc
1.33.3
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
google-oauth-client@1.25.0
1.33.3
1
openkm/openkm-ce:6.3.113bc465a7461b
google-oauth-client@1.20.0
1.33.3
1
trinodb/trino:405ee80ab5eeab2
google-oauth-client@1.31.0
1.33.3
1
wistefan/mvf:lateste0887302b2d8
google-oauth-client@1.25.0
1.33.3
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
google-oauth-client@1.19.0
1.33.3
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
google-oauth-client@1.30.2
1.33.3
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
google-oauth-client@1.23.0
1.33.3
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
google-oauth-client@1.31.5
1.33.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.