StackRadar

CVE-2022-31690

High

Advisory

Published 1 Nov 2022In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
24
deployed by those charts
Fix available
1 of 1
affected package

spring-security-oauth2-client vulnerable to Privilege Escalation

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
spring-security-oauth2-clientmaven5.2.2.RELEASE, 5.3.4.RELEASE, 5.3.10.RELEASE, 5.4.5+7 more5.6.9, 5.7.524
OSV records
GHSA-32vj-v39g-jh23

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-oauth2-client@5.5.5
5.6.9

Open the chart page →

3,958
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-oauth2-client@5.3.10.RELEASE
5.6.9

Open the chart page →

12,513
scorpio-brokerfiware0.3.39 of 10See more

scorpio-broker fiware 0.3.3

9 of the 10 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-oauth2-client@5.6.0
5.6.9

Open the chart page →

55,600
scorpiobrokerfiware0.1.29 of 10See more

scorpiobroker fiware 0.1.2

9 of the 10 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-oauth2-client@5.6.0
5.6.9
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-oauth2-client@5.6.0
5.6.9

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-security-oauth2-client@5.6.0
5.6.9

Open the chart page →

5,286
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
dannielkil/book-backend:lateste3b479a55a69
spring-security-oauth2-client@5.7.3
5.7.5

Open the chart page →

9,122
elastictranscoderluiscajl0.46.03 of 4See more

elastictranscoder luiscajl 0.46.0

3 of the 4 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
spring-security-oauth2-client@5.5.0
5.6.9
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-security-oauth2-client@5.5.0
5.6.9
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
spring-security-oauth2-client@5.5.0
5.6.9

Open the chart page →

58,160
lavandaluiscajl0.0.1343 of 5See more

lavanda luiscajl 0.0.134

3 of the 5 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-security-oauth2-client@5.3.4.RELEASE
5.6.9
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-security-oauth2-client@5.3.4.RELEASE
5.6.9
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-security-oauth2-client@5.4.5
5.6.9

Open the chart page →

18,248
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
reportportal/service-authorization:5.7.09e73114dbd15
spring-security-oauth2-client@5.2.2.RELEASE
5.6.9

Open the chart page →

25,737
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-oauth2-client@5.6.5
5.6.9

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-oauth2-client@5.3.10.RELEASE
5.6.9

Open the chart page →

12,513
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
spring-security-oauth2-client@5.7.3
5.7.5

Open the chart page →

5,856
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-oauth2-client@5.3.10.RELEASE
5.6.9

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-oauth2-client@5.7.1
5.7.5

Open the chart page →

25,394
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-oauth2-client@5.6.1
5.6.9

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-31690.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-oauth2-client@5.6.1
5.6.9

Open the chart page →

28,605

Container images carrying it

24 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-oauth2-client@5.3.10.RELEASE
5.6.9
3
hookiesolutions/webhookie:latest0629694246ba
spring-security-oauth2-client@5.6.1
5.6.9
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-oauth2-client@5.6.0
5.6.9
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-oauth2-client@5.6.0
5.6.9
2
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-oauth2-client@5.6.5
5.6.9
1
dannielkil/book-backend:lateste3b479a55a69
spring-security-oauth2-client@5.7.3
5.7.5
1
elastictranscoder/media:627e21dc963ab3858c6b
spring-security-oauth2-client@5.5.0
5.6.9
1
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-security-oauth2-client@5.5.0
5.6.9
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
spring-security-oauth2-client@5.5.0
5.6.9
1
jhipster/jhipster-registry:latest7184525acd4d
spring-security-oauth2-client@5.7.3
5.7.5
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-security-oauth2-client@5.3.4.RELEASE
5.6.9
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-security-oauth2-client@5.3.4.RELEASE
5.6.9
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-security-oauth2-client@5.4.5
5.6.9
1
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-oauth2-client@5.5.5
5.6.9
1
reportportal/service-authorization:5.7.09e73114dbd15
spring-security-oauth2-client@5.2.2.RELEASE
5.6.9
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-security-oauth2-client@5.6.0
5.6.9
1
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-oauth2-client@5.7.1
5.7.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.