StackRadar

CVE-2022-36033

Medium

Advisory

Published 1 Sept 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
65
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 1
affected package

jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled

Carried by container images the latest versions of 65 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+10 more1.15.358
OSV records
GHSA-gp7f-rwcx-9369

Charts affected

65 by stars
ChartLatestAffected imagesRadar Score
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.15.3

Open the chart page →

3,633
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.15.3

Open the chart page →

27,537
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.15.3

Open the chart page →

27,558
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
jsoup@1.12.1
1.15.3

Open the chart page →

29,227
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.15.3

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.15.3

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.15.3

Open the chart page →

13,079
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.15.3

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.15.3

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.15.3

Open the chart page →

11,554
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.15.3

Open the chart page →

12,455
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.15.3

Open the chart page →

4,303
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jsoup@1.8.3
1.15.3

Open the chart page →

28,605
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jsoup@1.12.1
1.15.3

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.15.3

Open the chart page →

6,213

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/apollo:0.0.1055330b1b60c1
jsoup@1.12.1
1.15.3
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
jsoup@1.12.1
1.15.3
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
jsoup@1.12.1
1.15.3
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
jsoup@1.12.1
1.15.3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jsoup@1.8.3
1.15.3
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jsoup@1.12.1
1.15.3
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
jsoup@1.12.1
1.15.3
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
jsoup@1.12.1
1.15.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.