StackRadar

CVE-2022-40152

Medium

Advisory

Published 17 Sept 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.197
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
98
of 17,781 indexed, latest versions
Container images
111
deployed by those charts
Fix available
1 of 1
affected package

Denial of Service due to parser crash

Carried by container images the latest versions of 98 of 17,781 indexed charts deploy, on 111 images.

Affected packageAffected versionsFixed inImages
woodstox-coremaven5.0.3, 5.1.0, 5.2.0, 5.2.1+11 more5.4.0, 6.4.0111
OSV records
GHSA-3f7h-mf4q-vrm4

Charts affected

98 by stars
ChartLatestAffected imagesRadar Score
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
woodstox-core@5.3.0
5.4.0

Open the chart page →

9,342
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
woodstox-core@6.2.4
6.4.0

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
woodstox-core@5.0.3
5.4.0

Open the chart page →

19,215
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
woodstox-core@6.2.7
6.4.0

Open the chart page →

8,943
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
woodstox-core@6.2.4
6.4.0

Open the chart page →

12,581
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
woodstox-core@6.2.6
6.4.0

Open the chart page →

2,887
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
woodstox-core@5.1.0
5.4.0

Open the chart page →

27,949
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
woodstox-core@6.2.3
6.4.0

Open the chart page →

34,754
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
woodstox-core@5.0.3
5.4.0

Open the chart page →

6,102
hbasehbase0.1.72 of 4See more

hbase hbase 0.1.7

2 of the 4 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
woodstox-core@5.0.3
5.4.0
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
woodstox-core@5.3.0
5.4.0

Open the chart page →

10,540
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
woodstox-core@5.0.3
5.4.0

Open the chart page →

6,451
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
woodstox-core@5.3.0
5.4.0

Open the chart page →

8,541
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
woodstox-core@5.0.3
5.4.0

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
woodstox-core@5.0.3
5.4.0

Open the chart page →

8,221
delta-sharing-serverinseefrlab1.2.11 of 1See more

delta-sharing-server inseefrlab 1.2.1

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
deltaio/delta-sharing-server:0.2.08b75118187c5
woodstox-core@5.0.3
5.4.0

Open the chart page →

6,174
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
woodstox-core@6.0.1
6.4.0

Open the chart page →

10,777
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
woodstox-core@5.2.0
5.4.0

Open the chart page →

2,273
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
woodstox-core@5.0.3
5.4.0

Open the chart page →

7,929
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
woodstox-core@6.2.1
6.4.0

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
woodstox-core@6.2.1
6.4.0

Open the chart page →

4,599
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
woodstox-core@6.2.7
6.4.0

Open the chart page →

12,847
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
woodstox-core@6.2.6
6.4.0

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
woodstox-core@6.2.6
6.4.0

Open the chart page →

10,603
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
woodstox-core@6.1.1
6.4.0

Open the chart page →

3,633
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
woodstox-core@5.3.0
5.4.0

Open the chart page →

8,540
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
woodstox-core@6.0.2
6.4.0

Open the chart page →

36,215
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
woodstox-core@6.1.1
6.4.0

Open the chart page →

6,237
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
woodstox-core@5.0.3
5.4.0

Open the chart page →

9,606
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
woodstox-core@5.3.0
5.4.0

Open the chart page →

1,995
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
woodstox-core@5.3.0
5.4.0

Open the chart page →

21,211
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
woodstox-core@5.2.1
5.4.0

Open the chart page →

4,203
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
reportportal/service-authorization:5.7.09e73114dbd15
woodstox-core@5.0.3
5.4.0

Open the chart page →

25,737
smartsuggestsearchhub0.1.01 of 1See more

smartsuggest searchhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
commerceexperts/searchhub-smartsuggest-service:1.3.0341eebe7239b
woodstox-core@5.0.3
5.4.0

Open the chart page →

1,235
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
woodstox-core@6.2.1
6.4.0

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
woodstox-core@5.2.1
5.4.0

Open the chart page →

12,513
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
woodstox-core@6.2.1
6.4.0

Open the chart page →

5,856
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
woodstox-core@6.2.4
6.4.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
woodstox-core@6.2.4
6.4.0

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
woodstox-core@6.2.7
6.4.0

Open the chart page →

13,767
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
woodstox-core@5.2.1
5.4.0

Open the chart page →

12,513
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
woodstox-core@5.0.3
5.4.0

Open the chart page →

12,455
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
woodstox-core@5.3.0
5.4.0

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
woodstox-core@5.0.3
5.4.0

Open the chart page →

5,460
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
woodstox-core@6.2.7
6.4.0

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
woodstox-core@6.2.7
6.4.0
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
woodstox-core@6.0.3
6.4.0

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
woodstox-core@5.0.3
5.4.0

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
woodstox-core@6.2.1
6.4.0

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-40152.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
woodstox-core@6.2.1
6.4.0

Open the chart page →

6,213

Container images carrying it

111 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
vrijbrp/balie:developbc85c89530b9
woodstox-core@6.2.6
6.4.0
1
vrijbrp/balie-ws:developc6603cb829ea
woodstox-core@6.2.6
6.4.0
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
woodstox-core@6.0.3
6.4.0
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
woodstox-core@5.0.3
5.4.0
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
woodstox-core@5.3.0
5.4.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
woodstox-core@5.3.0
5.4.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
woodstox-core@5.0.3
5.4.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
woodstox-core@5.3.0
5.4.0
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
woodstox-core@5.3.0
5.4.0
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
woodstox-core@5.0.3
5.4.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
woodstox-core@6.0.3
6.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.