StackRadar

CVE-2022-22978

Critical

Advisory

Published 20 May 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.124
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
76
deployed by those charts
Fix available
2 of 2
affected packages

Authorization bypass in Spring Security

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 76 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven3.0.4, 3.2.10.RELEASE, 4.1.3.RELEASE, 4.2.2.RELEASE+25 more5.4.11, 5.5.7, 5.6.476
spring-security-webmaven3.2.10.RELEASE, 4.1.3.RELEASE, 4.1.4.RELEASE, 4.2.2.RELEASE+24 more5.4.11, 5.5.7, 5.6.471
OSV records
GHSA-hh32-7344-cg2f

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
spring-security-core@5.2.1.RELEASE
5.4.11

Open the chart page →

13,079
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-core@5.1.5.RELEASE
spring-security-web@5.1.5.RELEASE
5.4.11
5.4.11

Open the chart page →

6,101
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
spring-security-web@4.1.4.RELEASE
5.4.11
5.4.11

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.2.1-plain
5.4.11

Open the chart page →

18,756
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-core@5.2.1.RELEASE
spring-security-web@5.2.1.RELEASE
5.4.11
5.4.11

Open the chart page →

12,513
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
spring-security-web@5.6.1
5.6.4
5.6.4

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
spring-security-web@5.6.1
5.6.4
5.6.4

Open the chart page →

28,605

Container images carrying it

76 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
spring-security-web@4.1.4.RELEASE
5.4.11
5.4.11
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
spring-security-core@5.4.1
spring-security-web@5.4.1
5.4.11
5.4.11
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-security-core@5.4.5
spring-security-web@5.4.5
5.4.11
5.4.11
1
nacos/nacos-server:1.4.1fe6e5688cdf3
spring-security-core@5.1.12.RELEASE
spring-security-web@5.1.12.RELEASE
5.4.11
5.4.11
1
openkm/openkm-ce:6.3.113bc465a7461b
spring-security-core@3.2.10.RELEASE
spring-security-web@3.2.10.RELEASE
5.4.11
5.4.11
1
platform9community/api-gateway:latest40a4970de568
spring-security-core@5.3.3.RELEASE
spring-security-web@5.3.3.RELEASE
5.4.11
5.4.11
1
platform9community/customers-service:latest2089811e5cc6
spring-security-core@5.3.3.RELEASE
spring-security-web@5.3.3.RELEASE
5.4.11
5.4.11
1
platform9community/vets-service:latestd1165c94dfb3
spring-security-core@5.3.3.RELEASE
spring-security-web@5.3.3.RELEASE
5.4.11
5.4.11
1
platform9community/visits-service:latest8d11b50368c6
spring-security-core@5.3.3.RELEASE
spring-security-web@5.3.3.RELEASE
5.4.11
5.4.11
1
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-core@5.5.5
spring-security-web@5.5.5
5.5.7
5.5.7
1
reportportal/service-api:5.7.29df41f8fb320
spring-security-core@5.2.4.RELEASE
spring-security-web@5.2.4.RELEASE
5.4.11
5.4.11
1
reportportal/service-authorization:5.7.09e73114dbd15
spring-security-core@5.2.4.RELEASE
spring-security-web@5.2.4.RELEASE
5.4.11
5.4.11
1
rundeck/rundeck:3.2.74d64fe56f767
spring-security-core@4.2.13.RELEASE
spring-security-web@4.2.13.RELEASE
5.4.11
5.4.11
1
rundeck/rundeck:3.0.16b13e8059ad72
spring-security-core@4.2.7.RELEASE
spring-security-web@4.2.7.RELEASE
5.4.11
5.4.11
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
1
seataio/seata-server:1.5.1ee1ed55f4144
spring-security-core@5.4.9
spring-security-web@5.4.9
5.4.11
5.4.11
1
seldonio/apife:0.2.7ba81b17f00eb
spring-security-core@4.2.9.RELEASE
spring-security-web@4.2.9.RELEASE
5.4.11
5.4.11
1
seldonio/apife:0.3.1eea0d3f578ca
spring-security-core@4.2.9.RELEASE
spring-security-web@4.2.9.RELEASE
5.4.11
5.4.11
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.2.1-plain
5.4.11
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
spring-security-core@5.2.1.RELEASE
spring-security-web@5.2.1.RELEASE
5.4.11
5.4.11
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-security-core@5.3.3.RELEASE
spring-security-web@5.3.3.RELEASE
5.4.11
5.4.11
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
spring-security-core@5.2.4.RELEASE
spring-security-web@5.2.4.RELEASE
5.4.11
5.4.11
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-core@5.1.5.RELEASE
spring-security-web@5.1.5.RELEASE
5.4.11
5.4.11
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-security-core@5.6.2
spring-security-web@5.6.2
5.6.4
5.6.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.