StackRadar

CVE-2022-22978

Critical

Advisory

Published 20 May 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.124
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
76
deployed by those charts
Fix available
2 of 2
affected packages

Authorization bypass in Spring Security

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 76 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven3.0.4, 3.2.10.RELEASE, 4.1.3.RELEASE, 4.2.2.RELEASE+25 more5.4.11, 5.5.7, 5.6.476
spring-security-webmaven3.2.10.RELEASE, 4.1.3.RELEASE, 4.1.4.RELEASE, 4.2.2.RELEASE+24 more5.4.11, 5.5.7, 5.6.471
OSV records
GHSA-hh32-7344-cg2f

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
spring-security-core@5.2.1.RELEASE
5.4.11

Open the chart page →

13,079
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-core@5.1.5.RELEASE
spring-security-web@5.1.5.RELEASE
5.4.11
5.4.11

Open the chart page →

6,101
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
spring-security-web@4.1.4.RELEASE
5.4.11
5.4.11

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.2.1-plain
5.4.11

Open the chart page →

18,756
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-core@5.2.1.RELEASE
spring-security-web@5.2.1.RELEASE
5.4.11
5.4.11

Open the chart page →

12,513
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
spring-security-web@5.6.1
5.6.4
5.6.4

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-22978.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
spring-security-web@5.6.1
5.6.4
5.6.4

Open the chart page →

28,605

Container images carrying it

76 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-core@5.2.1.RELEASE
spring-security-web@5.2.1.RELEASE
5.4.11
5.4.11
3
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
2
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
spring-security-web@5.6.1
5.6.4
5.6.4
2
nacos/nacos-server:v2.1.0dcf04549c6d7
spring-security-core@5.1.12.RELEASE
spring-security-web@5.1.12.RELEASE
5.4.11
5.4.11
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-core@5.6.0
spring-security-web@5.6.0
5.6.4
5.6.4
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
spring-security-core@5.5.0
spring-security-web@5.5.0
5.5.7
5.5.7
1
andrianrf/bpjstk-service:latest46abe878d9d8
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
andrianrf/iso-client:latestba560086ce15
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
apache/nifi-registry:1.14.0090b7f87ec7f
spring-security-core@5.5.0
spring-security-web@5.5.0
5.5.7
5.5.7
1
apache/nifi-registry:0.8.0974efa2f21da
spring-security-core@5.2.2.RELEASE
spring-security-web@5.2.2.RELEASE
5.4.11
5.4.11
1
atlassian/confluence-server:7.10.03b9222ab32ef
spring-security-core@4.2.16.RELEASE
5.4.11
1
atlassian/jira-software:8.14.037bc46cbec1a
spring-security-core@5.2.1.RELEASE
5.4.11
1
atlassian/jira-software:9.7.264a75aa4ec4e
spring-security-core@5.4.5
5.4.11
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
spring-security-core@5.3.3.RELEASE
spring-security-web@5.3.3.RELEASE
5.4.11
5.4.11
1
choerodon/event-store-service:0.8.03c94c97f6f69
spring-security-core@4.2.2.RELEASE
spring-security-web@4.2.2.RELEASE
5.4.11
5.4.11
1
craigwillis/c2metadata-bd:latestae317d7e4724
spring-security-core@4.1.3.RELEASE
spring-security-web@4.1.3.RELEASE
5.4.11
5.4.11
1
drpcorg/dshackle:0.54.08858fae1859d
spring-security-core@5.5.3
spring-security-web@5.5.3
5.5.7
5.5.7
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
spring-security-core@4.2.17.RELEASE
spring-security-web@4.2.17.RELEASE
5.4.11
5.4.11
1
elastictranscoder/media:627e21dc963ab3858c6b
spring-security-core@5.5.0
spring-security-web@5.5.0
5.5.7
5.5.7
1
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-security-core@5.5.0
spring-security-web@5.5.0
5.5.7
5.5.7
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
spring-security-core@5.5.0
spring-security-web@5.5.0
5.5.7
5.5.7
1
emeraldpay/dshackle:0.14.0126f0ae0b388
spring-security-core@5.5.3
spring-security-web@5.5.3
5.5.7
5.5.7
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
spring-security-core@5.5.3
spring-security-web@5.5.3
5.5.7
5.5.7
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-security-core@5.4.1
5.4.11
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
spring-security-core@5.3.6.RELEASE
spring-security-web@5.3.6.RELEASE
5.4.11
5.4.11
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-security-core@5.3.4.RELEASE
spring-security-web@5.3.4.RELEASE
5.4.11
5.4.11
1
gocd/gocd-server:v19.3.02da45cb09d57
spring-security-core@4.2.11.RELEASE
spring-security-web@4.2.11.RELEASE
5.4.11
5.4.11
1
gocd/gocd-server:v26.1.0720d1012b93f
spring-security-core@4.2.20.RELEASE
spring-security-web@4.2.20.RELEASE
5.4.11
5.4.11
1
gotson/komga:0.99.49b15ea6bfc30
spring-security-core@5.5.0
spring-security-web@5.4.6
5.5.7
5.4.11
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-security-core@5.6.2
spring-security-web@5.6.2
5.6.4
5.6.4
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-security-core@5.6.2
spring-security-web@5.6.2
5.6.4
5.6.4
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-security-core@5.6.2
spring-security-web@5.6.2
5.6.4
5.6.4
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-security-core@5.6.2
spring-security-web@5.6.2
5.6.4
5.6.4
1
housewrecker/gaps:latestf417dd0a7547
spring-security-core@5.6.2
spring-security-web@5.6.2
5.6.4
5.6.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.