StackRadar

CVE-2022-31692

Critical

Advisory

Published 1 Nov 2022In the index since 8 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.036
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
30
deployed by those charts
Fix available
1 of 1
affected package

Spring Security authorization rules can be bypassed via forward or include dispatcher types

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven5.6.0, 5.6.1, 5.6.2, 5.6.5+4 more5.6.9, 5.7.530
OSV records
GHSA-mmmh-wcxm-2wr4

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-security-core@5.7.3
5.7.5

Open the chart page →

6,639
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-security-core@5.6.2
5.6.9

Open the chart page →

5,489
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
spring-security-core@5.7.4
5.7.5

Open the chart page →

2,231
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-core@5.7.1
5.7.5

Open the chart page →

4,145
scorpio-brokerfiware0.3.39 of 10See more

scorpio-broker fiware 0.3.3

9 of the 10 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-core@5.6.0
5.6.9

Open the chart page →

55,600
scorpiobrokerfiware0.1.29 of 10See more

scorpiobroker fiware 0.1.2

9 of the 10 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-core@5.6.0
5.6.9
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-core@5.6.0
5.6.9

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-security-core@5.6.0
5.6.9

Open the chart page →

5,286
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
spring-security-core@5.6.2
5.6.9

Open the chart page →

8,943
siembolgresearch0.1.62 of 4See more

siembol gresearch 0.1.6

2 of the 4 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-core@5.7.4
5.7.5
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-core@5.7.4
5.7.5

Open the chart page →

14,312
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
dannielkil/book-backend:lateste3b479a55a69
spring-security-core@5.7.3
5.7.5

Open the chart page →

9,122
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-security-core@5.7.2
5.7.5

Open the chart page →

5,875
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-security-core@5.7.2
5.7.5

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
spring-security-core@5.7.2
5.7.5

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-security-core@5.7.2
5.7.5

Open the chart page →

5,873
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-security-core@5.6.2
5.6.9

Open the chart page →

13,607
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-security-core@5.6.2
5.6.9

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-security-core@5.6.2
5.6.9

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-security-core@5.6.2
5.6.9

Open the chart page →

13,455
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-core@5.6.5
5.6.9

Open the chart page →

8,804
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
spring-security-core@5.7.3
5.7.5

Open the chart page →

5,856
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-core@5.7.1
5.7.5

Open the chart page →

25,394
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.6.9

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-31692.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.6.9

Open the chart page →

28,605

Container images carrying it

30 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.6.9
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-core@5.6.0
5.6.9
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-core@5.6.0
5.6.9
2
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-core@5.6.5
5.6.9
1
apimap/api:v1.8.11ae2b3ab00177
spring-security-core@5.7.4
5.7.5
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-core@5.7.1
5.7.5
1
dannielkil/book-backend:lateste3b479a55a69
spring-security-core@5.7.3
5.7.5
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-core@5.7.4
5.7.5
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-core@5.7.4
5.7.5
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-security-core@5.6.2
5.6.9
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-security-core@5.6.2
5.6.9
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-security-core@5.6.2
5.6.9
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-security-core@5.6.2
5.6.9
1
housewrecker/gaps:latestf417dd0a7547
spring-security-core@5.6.2
5.6.9
1
jhipster/jhipster-registry:latest7184525acd4d
spring-security-core@5.7.3
5.7.5
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-security-core@5.6.0
5.6.9
1
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-core@5.7.1
5.7.5
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-security-core@5.7.2
5.7.5
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-security-core@5.7.2
5.7.5
1
vlebediantsev/registration-ms-final:latest427af418b75e
spring-security-core@5.7.2
5.7.5
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-security-core@5.7.2
5.7.5
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-security-core@5.7.3
5.7.5
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-security-core@5.6.2
5.6.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.