StackRadar

CVE-2022-36364

High

Advisory

Published 29 Jul 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.030
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Apache Calcite Avatica JDBC driver arbitrary code execution

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
avatica-coremaven1.10.0, 1.11.0, 1.12.0, 1.13.0+2 more1.22.09
OSV records
GHSA-w7f5-jrpr-5c2m

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
avatica-core@1.13.0
1.22.0

Open the chart page →

6,048
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
avatica-core@1.11.0
1.22.0

Open the chart page →

7,166
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
avatica-core@1.11.0
1.22.0

Open the chart page →

7,335
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
avatica-core@1.10.0
1.22.0

Open the chart page →

6,165
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
avatica-core@1.18.0
1.22.0

Open the chart page →

24,930
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
avatica-core@1.13.0
1.22.0

Open the chart page →

16,860
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
avatica-core@1.12.0
1.22.0

Open the chart page →

39,349
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
avatica-core@1.13.0
1.22.0

Open the chart page →

15,855
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
avatica-core@1.20.0
1.22.0

Open the chart page →

21,211
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
avatica-core@1.18.0
1.22.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
avatica-core@1.18.0
1.22.0

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-36364.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
avatica-core@1.20.0
1.22.0

Open the chart page →

13,767

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
avatica-core@1.18.0
1.22.0
3
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
avatica-core@1.13.0
1.22.0
2
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
avatica-core@1.11.0
1.22.0
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
avatica-core@1.12.0
1.22.0
1
library/solr:8.7.0d124efd81fbb
avatica-core@1.13.0
1.22.0
1
library/storm:2.4.0bd5d420506d6
avatica-core@1.10.0
1.22.0
1
sslhep/hive-metastore:3.1.39e80af083079
avatica-core@1.11.0
1.22.0
1
trinodb/trino:45038c6f24ab1a4
avatica-core@1.20.0
1.22.0
1
trinodb/trino:405ee80ab5eeab2
avatica-core@1.20.0
1.22.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.