StackRadar

CVE-2022-33980

Critical

Advisory

Published 7 Jul 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.451
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Code injection in Apache Commons Configuration

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
commons-configuration2maven2.4, 2.5, 2.72.8.010
OSV records
GHSA-xj57-8qj4-c4m6

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
commons-configuration2@2.7
2.8.0

Open the chart page →

2,640
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
commons-configuration2@2.7
2.8.0

Open the chart page →

4,419
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
commons-configuration2@2.7
2.8.0

Open the chart page →

2,751
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
commons-configuration2@2.7
2.8.0

Open the chart page →

4,621
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
commons-configuration2@2.4
2.8.0

Open the chart page →

9,144
accumulogaffer2.2.11 of 4See more

accumulo gaffer 2.2.1

1 of the 4 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
commons-configuration2@2.5
2.8.0

Open the chart page →

16,892
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-configuration2@2.7
2.8.0

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-configuration2@2.7
2.8.0

Open the chart page →

19,215
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
commons-configuration2@2.7
2.8.0

Open the chart page →

12,581
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
commons-configuration2@2.7
2.8.0

Open the chart page →

2,640
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-33980.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
commons-configuration2@2.5
2.8.0

Open the chart page →

13,605

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/neo4j:4.3.2-enterprise56a9453c4064
commons-configuration2@2.7
2.8.0
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-configuration2@2.7
2.8.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-configuration2@2.7
2.8.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
commons-configuration2@2.5
2.8.0
1
gchq/accumulo:2.0.1c460bb587d6d
commons-configuration2@2.5
2.8.0
1
gocd/gocd-server:v19.3.02da45cb09d57
commons-configuration2@2.4
2.8.0
1
gotson/komga:0.99.49b15ea6bfc30
commons-configuration2@2.7
2.8.0
1
library/neo4j:4.2.4348e3f56faa2
commons-configuration2@2.7
2.8.0
1
vromero/activemq-artemis:2.16.0408d6a46b153
commons-configuration2@2.7
2.8.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-configuration2@2.7
2.8.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.