StackRadar

CVE-2022-34169

High

Advisory

Published 19 Jul 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.810
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
51
deployed by those charts
Fix available
4 of 4
affected packages

Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
xalanmaven2.7.1, 2.7.1.jbossorg-4, 2.7.1.jbossorg-5, 2.7.22.7.328
openjdk-8deb8u151-b12-0ubuntu0.16.04.2, 8u171-b11-0ubuntu0.16.04.1, 8u191-b12-2ubuntu0.16.04.1, 8u212-b03-0ubuntu1.18.04.1+5 more8u342-b07-0ubuntu1~16.04, 8u342-b07-0ubuntu1~18.04, 8u342-b07-0ubuntu1~20.0413
openjdk-ltsdeb11.0.3+7-1ubuntu2~18.04.1, 11.0.8+10-0ubuntu1~18.04.1, 11.0.11+9-0ubuntu2~20.04, 11.0.13+8-0ubuntu1~20.04+1 more11.0.16+8-0ubuntu1~18.04, 11.0.16+8-0ubuntu1~20.0410
openjdk-17deb17.0.3+7-0ubuntu0.20.04.117.0.4+8-1~20.041
OSV records
GHSA-9339-86wc-4qgfUBUNTU-CVE-2022-34169
Also known as
BIT-java-2022-34169, BIT-java-min-2022-34169, BIT-jre-2022-34169, USN-5546-1, USN-5546-2

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2022-34169.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
xalan@2.7.2
2.7.3

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-34169.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
openjdk-8@8u312-b07-0ubuntu1~18.04
8u342-b07-0ubuntu1~18.04

Open the chart page →

14,493
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-34169.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.16+8-0ubuntu1~20.04

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2022-34169.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
openjdk-lts@11.0.11+9-0ubuntu2~20.04
11.0.16+8-0ubuntu1~20.04
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
xalan@2.7.1.jbossorg-4
2.7.3

Open the chart page →

28,605

Container images carrying it

51 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openjdk-8@8u222-b10-1ubuntu1~16.04.1
8u342-b07-0ubuntu1~16.04
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.