StackRadar

CVE-2022-25647

High

Advisory

Published 3 May 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.122
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
141
deployed by those charts
Fix available
1 of 1
affected package

Deserialization of Untrusted Data in Gson

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 141 images.

Affected packageAffected versionsFixed inImages
gsonmaven2.6.2, 2.7, 2.8.0, 2.8.1+5 more2.8.9141
OSV records
GHSA-4jrv-ppp4-jm57
Also known as
SNYK-JAVA-COMGOOGLECODEGSON-1730327

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
gson@2.8.5
2.8.9

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
gson@2.8.5
2.8.9

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
gson@2.8.6
2.8.9

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
gson@2.8.6
2.8.9

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
gson@2.8.6
2.8.9

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
gson@2.8.5
2.8.9

Open the chart page →

6,213

Container images carrying it

141 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
gson@2.8.6
2.8.9
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
gson@2.7
2.8.9
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
gson@2.8.5
2.8.9
1
nacos/nacos-server:1.4.1fe6e5688cdf3
gson@2.8.6
2.8.9
1
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
gson@2.8.6
2.8.9
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
gson@2.8.8
2.8.9
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
gson@2.8.0
2.8.9
1
onosproject/onos:2.2.144914a8d4b3f
gson@2.7
2.8.9
1
opencord/ves-agent:1.0.04187e2a8c918
gson@2.8.5
2.8.9
1
openhab/openhab:3.2.0d0aa4af452c1
gson@2.8.6
2.8.9
1
openwhisk/invoker:1.0.0f5831ec85525
gson@2.7
2.8.9
1
oscarsotosanchez/planner:v1.0730c00a099b8
gson@2.8.6
2.8.9
1
owasp/dependency-track:3.8.0efc65e702ee1
gson@2.8.0
2.8.9
1
penpotapp/backend:2.2.147853d9bb9dd
gson@2.7
2.8.9
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
gson@2.7
2.8.9
1
rundeck/rundeck:3.2.74d64fe56f767
gson@2.8.2
2.8.9
1
rundeck/rundeck:3.0.16b13e8059ad72
gson@2.8.5
2.8.9
1
seldonio/apife:0.2.7ba81b17f00eb
gson@2.8.5
2.8.9
1
seldonio/apife:0.3.1eea0d3f578ca
gson@2.8.5
2.8.9
1
seldonio/cluster-manager:0.2.729e362bb1ba2
gson@2.8.5
2.8.9
1
signald/signald:0.18.20ffad7ccc2eb
gson@2.8.5
2.8.9
1
slagattollas/planner-practica:latestcecd95e31486
gson@2.8.6
2.8.9
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
gson@2.8.5
2.8.9
1
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
gson@2.8.6
2.8.9
1
sslhep/hive-metastore:3.1.39e80af083079
gson@2.8.1
2.8.9
1
torrespro/mca-worker:2.0.06d3bd305a1ba
gson@2.8.6
2.8.9
1
trinodb/trino:405ee80ab5eeab2
gson@2.8.5
2.8.9
1
voltha/voltha-onos:5.1.8e038acb950d3
gson@2.7
2.8.9
1
wavefronthq/proxy:9.2d1064d28f6eb
gson@2.8.2
2.8.9
1
wistefan/mvf:lateste0887302b2d8
gson@2.8.6
2.8.9
1
xeotek/kadeck:4.2.94c6b04d9ce55
gson@2.8.6
2.8.9
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
gson@2.8.6
2.8.9
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
gson@2.8.1
2.8.9
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
gson@2.7
2.8.9
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
gson@2.8.6
2.8.9
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
gson@2.8.6
2.8.9
1
ghcr.io/kvaps/linstor-satellite:v1.14.0a573fb9bc809
gson@2.8.6
2.8.9
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
gson@2.8.5
2.8.9
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
gson@2.8.8
2.8.9
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
gson@2.8.6
2.8.9
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
gson@2.8.2
2.8.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.