StackRadar

CVE-2022-0839

Critical

Advisory

Published 5 Mar 2022In the index since 8 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.030
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Improper Restriction of XML External Entity Reference in Liquibase

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
liquibase-coremaven3.1.1, 3.5.5, 3.6.2, 3.6.3+3 more4.8.09
OSV records
GHSA-jvfv-hrrc-6q72

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
liquibase-core@3.6.2
4.8.0

Open the chart page →

4,601
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
liquibase-core@4.3.5
4.8.0

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
liquibase-core@3.8.9
4.8.0

Open the chart page →

19,215
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
liquibase-core@3.6.3
4.8.0

Open the chart page →

7,498
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
liquibase-core@4.5.0
4.8.0

Open the chart page →

2,583
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
liquibase-core@4.5.0
4.8.0

Open the chart page →

2,600
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
liquibase-core@3.6.2
4.8.0

Open the chart page →

13,605
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
liquibase-core@3.1.1
4.8.0

Open the chart page →

3,164
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-0839.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
liquibase-core@3.5.5
4.8.0

Open the chart page →

28,605

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
liquibase-core@4.3.5
4.8.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
liquibase-core@3.6.2
4.8.0
1
metabase/metabase:v0.31.2ffb2dccacefc
liquibase-core@3.6.2
4.8.0
1
redestroyder/authorization-service:0.0.1740364a619fd
liquibase-core@4.5.0
4.8.0
1
redestroyder/business-service:0.0.1db03499a0726
liquibase-core@4.5.0
4.8.0
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
liquibase-core@3.6.3
4.8.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
liquibase-core@3.8.9
4.8.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
liquibase-core@3.5.5
4.8.0
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
liquibase-core@3.1.1
4.8.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.