StackRadar

CVE-2022-23221

Critical

Advisory

Published 21 Jan 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.648
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
45
deployed by those charts
Fix available
1 of 1
affected package

Arbitrary code execution in H2 Console

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 45 images.

Affected packageAffected versionsFixed inImages
h2maven1.4.198, 1.4.199, 1.4.2002.1.21045
OSV records
GHSA-45hx-wfhj-473x

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
h2@1.4.200
2.1.210

Open the chart page →

4,946
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
h2@1.4.200
2.1.210

Open the chart page →

13,605
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
h2@1.4.200
2.1.210

Open the chart page →

4,278
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
h2@1.4.200
2.1.210

Open the chart page →

13,767
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
h2@1.4.200
2.1.210

Open the chart page →

12,513
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210

Open the chart page →

20,190
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
h2@1.4.199
2.1.210

Open the chart page →

5,460
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-23221.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
h2@1.4.199
2.1.210

Open the chart page →

6,213

Container images carrying it

45 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.1.210
79
apache/shenyu-admin:2.4.2e8b7c4ddd069
h2@1.4.200
2.1.210
3
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
h2@1.4.200
2.1.210
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
h2@1.4.200
2.1.210
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
h2@1.4.200
2.1.210
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
h2@1.4.200
2.1.210
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
h2@1.4.200
2.1.210
2
andrianrf/bpjstk-service:latest46abe878d9d8
h2@1.4.200
2.1.210
1
andrianrf/iso-client:latestba560086ce15
h2@1.4.200
2.1.210
1
apache/nifi-registry:1.14.0090b7f87ec7f
h2@1.4.199
2.1.210
1
apache/nifi-registry:0.8.0974efa2f21da
h2@1.4.199
2.1.210
1
apache/shenyu-admin:2.5.1e2be712fc4f4
h2@1.4.200
2.1.210
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
h2@1.4.200
2.1.210
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
h2@1.4.200
2.1.210
1
atlassian/confluence-server:7.10.03b9222ab32ef
h2@1.4.200
2.1.210
1
beastob/url-shortener:1.0.299a49885ab33
h2@1.4.200
2.1.210
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
h2@1.4.200
2.1.210
1
eikek0/sharry:1.8.0661ff3ef42cd
h2@1.4.200
2.1.210
1
esperotech/yaade:latest24d2d692d948
h2@1.4.200
2.1.210
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
h2@1.4.200
2.1.210
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
h2@1.4.200
2.1.210
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
h2@1.4.200
2.1.210
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
h2@1.4.200
2.1.210
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
h2@1.4.200
2.1.210
1
gocd/gocd-server:v26.1.0720d1012b93f
h2@1.4.200
2.1.210
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
h2@1.4.199
2.1.210
1
library/sonarqube:8.9.2-community88cd63154d4b
h2@1.4.199
2.1.210
1
library/sonarqube:8.2-communitya246bc64207e
h2@1.4.199
2.1.210
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
h2@1.4.199
2.1.210
1
library/sonarqube:8.9-communityeb2f0be32efd
h2@1.4.199
2.1.210
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
h2@1.4.199
2.1.210
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
h2@1.4.199
2.1.210
1
owasp/dependency-track:3.8.0efc65e702ee1
h2@1.4.200
2.1.210
1
remche/shinyproxy:2.6.18bcda8a04d3b
h2@1.4.200
2.1.210
1
rundeck/rundeck:3.2.74d64fe56f767
h2@1.4.199
2.1.210
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
h2@1.4.200
2.1.210
1
sismics/docs:v1.10f4b0ef019cf1
h2@1.4.199
2.1.210
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
h2@1.4.200
2.1.210
1
sonatype/nexus3:3.58.1586060431b64
h2@1.4.200
2.1.210
1
trinodb/trino:405ee80ab5eeab2
h2@1.4.200
2.1.210
1
xeotek/kadeck:4.2.94c6b04d9ce55
h2@1.4.198
2.1.210
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
h2@1.4.200
2.1.210
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
h2@1.4.200
2.1.210
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
h2@1.4.200
2.1.210
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
h2@1.4.200
2.1.210
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.