StackRadar

CVE-2022-36033

Medium

Advisory

Published 1 Sept 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
65
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 1
affected package

jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled

Carried by container images the latest versions of 65 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
jsoupmaven1.6.1, 1.7.1, 1.7.2, 1.8.1+10 more1.15.358
OSV records
GHSA-gp7f-rwcx-9369

Charts affected

65 by stars
ChartLatestAffected imagesRadar Score
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.15.3

Open the chart page →

3,633
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.15.3

Open the chart page →

27,537
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.15.3

Open the chart page →

27,558
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
jsoup@1.12.1
1.15.3

Open the chart page →

29,227
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.15.3

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.15.3

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.15.3

Open the chart page →

13,079
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.15.3

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.15.3

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.15.3

Open the chart page →

11,554
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.15.3

Open the chart page →

12,455
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.15.3

Open the chart page →

4,303
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jsoup@1.8.3
1.15.3

Open the chart page →

28,605
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
jsoup@1.12.1
1.15.3

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-36033.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.15.3

Open the chart page →

6,213

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mastercloudapps/planner:v1.2340a950b311b2
jsoup@1.12.1
1.15.3
4
codeurjc/planner:v1.0800cf520c245
jsoup@1.12.1
1.15.3
3
linuxserver/ubooquity:2.1.2-ls369932d6759112
jsoup@1.8.3
1.15.3
2
opensearchproject/opensearch:2.1.04254021a8c71
jsoup@1.14.3
1.15.3
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
jsoup@1.12.1
1.15.3
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
jsoup@1.14.2
1.15.3
2
adagber/planner:v1.0e5c1ed097752
jsoup@1.12.1
1.15.3
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
jsoup@1.11.3
1.15.3
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
jsoup@1.12.1
1.15.3
1
arturisimo/planner:v1.0fff9de644941
jsoup@1.12.1
1.15.3
1
assistiot/automated_configuration:latest23f195a7a26a
jsoup@1.14.3
1.15.3
1
assistiot/identity-manager_kc:latest0df4b4fa899a
jsoup@1.14.2
1.15.3
1
atlassian/confluence-server:7.10.03b9222ab32ef
jsoup@1.9.2
1.15.3
1
atlassian/jira-software:8.14.037bc46cbec1a
jsoup@1.8.3
1.15.3
1
atlassian/jira-software:9.7.264a75aa4ec4e
jsoup@1.12.1
1.15.3
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
jsoup@1.11.3
1.15.3
1
craigwillis/c2metadata-bd:latestae317d7e4724
jsoup@1.7.2
1.15.3
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
jsoup@1.12.1
1.15.3
1
emcniece/dockeryourxyzzy:404eccbccc15c
jsoup@1.11.2
1.15.3
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
jsoup@1.14.3
1.15.3
1
fiware/mintaka:0.7.092a3c5cf43c0
jsoup@1.12.1
1.15.3
1
fiware/mintaka:latestefc6793388cc
jsoup@1.12.1
1.15.3
1
gotson/komga:0.99.49b15ea6bfc30
jsoup@1.13.1
1.15.3
1
hivemq/hivemq4:dns-4.5.144d194450d48e
jsoup@1.14.3
1.15.3
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
jsoup@1.14.2
1.15.3
1
hotavneesh/eclipse-jdtls:latesta4579b163414
jsoup@1.14.2
1.15.3
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
jsoup@1.12.1
1.15.3
1
hugohg34/planner:0.0.2171f61e8d7e2
jsoup@1.12.1
1.15.3
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
jsoup@1.7.2
1.15.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
jsoup@1.10.3
1.15.3
1
ibmcom/microclimate-theia:lateste17bdccc5030
jsoup@1.9.2
1.15.3
1
jenkinsci/jenkins:2.67a1f33f004659
jsoup@1.7.1
1.15.3
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
jsoup@1.13.1
1.15.3
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
jsoup@1.14.2
1.15.3
1
lourdesmorente/new-planner:1.0.0608745878cdb
jsoup@1.12.1
1.15.3
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
jsoup@1.10.3
1.15.3
1
molynx/planner:v1441c9f52f092
jsoup@1.12.1
1.15.3
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
jsoup@1.7.2
1.15.3
1
owasp/dependency-track:3.8.0efc65e702ee1
jsoup@1.11.3
1.15.3
1
pcarrascoponce/planner:v1.0981fc482442c
jsoup@1.12.1
1.15.3
1
pedrocesarti/jmeter-docker:3.314851f144f57
jsoup@1.10.3
1.15.3
1
penpotapp/exporter:2.2.15c835ffd87ab
jsoup@1.7.2
1.15.3
1
raykrueger/riemann:0.2.14c8baf3de57bb
jsoup@1.6.1
1.15.3
1
sismics/docs:v1.10f4b0ef019cf1
jsoup@1.13.1
1.15.3
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
jsoup@1.12.1
1.15.3
1
xetusoss/archiva:v2.2.588f25242b9ee
jsoup@1.7.2
1.15.3
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
jsoup@1.8.1
1.15.3
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jsoup@1.9.1
1.15.3
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
jsoup@1.11.3
1.15.3
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
jsoup@1.12.1
1.15.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.