StackRadar

CVE-2022-25647

High

Advisory

Published 3 May 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.122
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
141
deployed by those charts
Fix available
1 of 1
affected package

Deserialization of Untrusted Data in Gson

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 141 images.

Affected packageAffected versionsFixed inImages
gsonmaven2.6.2, 2.7, 2.8.0, 2.8.1+5 more2.8.9141
OSV records
GHSA-4jrv-ppp4-jm57
Also known as
SNYK-JAVA-COMGOOGLECODEGSON-1730327

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
gson@2.8.5
2.8.9

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
gson@2.8.5
2.8.9

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
gson@2.8.6
2.8.9

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
gson@2.8.6
2.8.9

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
gson@2.8.6
2.8.9

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-25647.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
gson@2.8.5
2.8.9

Open the chart page →

6,213

Container images carrying it

141 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flyway/flyway:6.4.422d97ceb0c47
gson@2.8.6
2.8.9
79
gradiant/hbase-base:2.0.1a1ee6de94c04
gson@2.8.1
2.8.9
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
gson@2.8.6
2.8.9
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
gson@2.8.0
2.8.9
3
library/solr:8.11.18c5f7881cebb
gson@2.7
2.8.9
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
gson@2.8.6
2.8.9
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
gson@2.8.2
2.8.9
2
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
gson@2.8.6
2.8.9
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
gson@2.8.6
2.8.9
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
gson@2.8.6
2.8.9
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
gson@2.8.6
2.8.9
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
gson@2.8.6
2.8.9
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
gson@2.8.6
2.8.9
2
nacos/nacos-server:v2.1.0dcf04549c6d7
gson@2.8.6
2.8.9
2
opensearchproject/opensearch:1.1.0967d7f57f72f
gson@2.8.6
2.8.9
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
gson@2.8.5
2.8.9
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
gson@2.8.1
2.8.9
1
amartinm82/planner:v2.01184353ff57b
gson@2.8.6
2.8.9
1
andrianrf/bpjstk-service:latest46abe878d9d8
gson@2.8.6
2.8.9
1
apache/bookkeeper:4.14.5a7d9970c148f
gson@2.8.6
2.8.9
1
apache/drill:1.21.11f96558fd292
gson@2.8.5
2.8.9
1
apache/druid:29.0.10cef139b6bf1
gson@2.8.6
2.8.9
1
apache/iotdb:0.11.28647309f95d1
gson@2.8.6
2.8.9
1
apache/iotdb:0.13.3-nodeafa47bf1692a
gson@2.8.8
2.8.9
1
apachepulsar/pulsar:2.6.14db6ff0b4045
gson@2.8.2
2.8.9
1
apachepulsar/pulsar:2.9.0d056c89b7131
gson@2.8.6
2.8.9
1
apachepulsar/pulsar:2.8.2d538416d5afe
gson@2.8.6
2.8.9
1
apache/rocketmq:4.9.35ac2a4e0f627
gson@2.8.6
2.8.9
1
apache/shenyu-admin:2.5.1e2be712fc4f4
gson@2.8.6
2.8.9
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
gson@2.8.6
2.8.9
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
gson@2.8.6
2.8.9
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
gson@2.8.6
2.8.9
1
apache/skywalking-ui:8.1.067d50e4deff4
gson@2.8.2
2.8.9
1
apache/skywalking-ui:8.9.180530f0308a5
gson@2.8.2
2.8.9
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
gson@2.8.6
2.8.9
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
gson@2.8.6
2.8.9
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
gson@2.7
2.8.9
1
atlassian/confluence-server:7.10.03b9222ab32ef
gson@2.8.6
2.8.9
1
atlassian/jira-software:8.14.037bc46cbec1a
gson@2.8.5
2.8.9
1
atlassian/jira-software:9.7.264a75aa4ec4e
gson@2.8.6
2.8.9
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
gson@2.8.6
2.8.9
1
biospheere/promcord:latest16d4fd269e66
gson@2.8.8
2.8.9
1
choerodon/event-store-service:0.8.03c94c97f6f69
gson@2.8.0
2.8.9
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
gson@2.8.6
2.8.9
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
gson@2.8.6
2.8.9
1
confluentinc/cp-kafka:5.4.01bbda887bc53
gson@2.8.5
2.8.9
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
gson@2.7
2.8.9
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
gson@2.8.6
2.8.9
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
gson@2.8.6
2.8.9
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
gson@2.8.6
2.8.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.