StackRadar

CVE-2022-22965

CriticalKEV

Advisory

Published 31 Mar 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.996
100th percentile
CISA KEV
Listed
since 4 Apr 2022
Charts affected
208
of 17,781 indexed, latest versions
Container images
156
deployed by those charts
Fix available
5 of 5
affected packages

Remote Code Execution in Spring Framework

Carried by container images the latest versions of 208 of 17,781 indexed charts deploy, on 156 images.

Affected packageAffected versionsFixed inImages
spring-beansmaven2.5.6.SEC03, 3.0.7, 3.0.7.RELEASE, 3.2.18.RELEASE+50 more5.2.20.RELEASE, 5.3.18156
spring-webmvcmaven2.5.6.SEC03, 3.2.18.RELEASE, 4.3.1.RELEASE, 4.3.2.RELEASE+41 more5.2.20.RELEASE, 5.3.18106
spring-boot-starter-webmaven1.4.0.RELEASE, 1.5.2.RELEASE, 1.5.3.RELEASE, 1.5.4.RELEASE+28 more2.5.12, 2.6.668
spring-webfluxmaven5.2.2.RELEASE, 5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1+5 more5.2.20.RELEASE, 5.3.1836
spring-boot-starter-webfluxmaven2.2.2.RELEASE, 2.3.1.RELEASE, 2.3.2.RELEASE, 2.3.3.RELEASE+2 more2.5.12, 2.6.69
OSV records
GHSA-36p3-wjmg-h94x

Charts affected

208 by stars
ChartLatestAffected imagesRadar Score
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-beans@5.2.7.RELEASE
spring-boot-starter-web@2.3.1.RELEASE
spring-webmvc@5.2.7.RELEASE
5.2.20.RELEASE
2.5.12
5.2.20.RELEASE

Open the chart page →

20,190
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
spring-beans@5.3.9
spring-webmvc@5.3.9
5.3.18
5.3.18

Open the chart page →

7,885
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-beans@5.2.7.RELEASE
spring-boot-starter-web@2.3.1.RELEASE
spring-webmvc@5.2.7.RELEASE
5.2.20.RELEASE
2.5.12
5.2.20.RELEASE

Open the chart page →

20,190
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
spring-beans@5.3.15
spring-webmvc@5.3.15
5.3.18
5.3.18

Open the chart page →

2,566
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-beans@5.3.15
spring-webflux@5.3.15
5.3.18
5.3.18

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-beans@5.3.15
spring-webflux@5.3.15
5.3.18
5.3.18

Open the chart page →

28,605
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
spring-beans@5.2.5.RELEASE
5.2.20.RELEASE

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-22965.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
spring-beans@5.1.2.RELEASE
5.2.20.RELEASE

Open the chart page →

6,213

Container images carrying it

156 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
spring-beans@5.2.3.RELEASE
spring-boot-starter-web@2.2.4.RELEASE
spring-webmvc@5.2.3.RELEASE
5.2.20.RELEASE
2.5.12
5.2.20.RELEASE
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-beans@5.2.7.RELEASE
spring-boot-starter-web@2.3.1.RELEASE
spring-webmvc@5.2.7.RELEASE
5.2.20.RELEASE
2.5.12
5.2.20.RELEASE
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
spring-beans@5.2.6.RELEASE
spring-boot-starter-web@2.2.7.RELEASE
spring-webmvc@5.2.6.RELEASE
5.2.20.RELEASE
2.5.12
5.2.20.RELEASE
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-beans@5.1.8.RELEASE
spring-boot-starter-web@2.1.6.RELEASE
spring-webmvc@5.1.8.RELEASE
5.2.20.RELEASE
2.5.12
5.2.20.RELEASE
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-beans@5.3.16
5.3.18
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
spring-beans@5.3.7
spring-boot-starter-web@2.5.0
spring-webmvc@5.3.7
5.3.18
2.5.12
5.3.18
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.