StackRadar

CVE-2022-42003

High

Advisory

Published 3 Oct 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
458
of 17,781 indexed, latest versions
Container images
388
deployed by those charts
Fix available
1 of 1
affected package

Uncontrolled Resource Consumption in Jackson-databind

Carried by container images the latest versions of 458 of 17,781 indexed charts deploy, on 388 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.4.0, 2.5.0, 2.5.3, 2.5.4+60 more2.12.7.1, 2.13.4.2388
OSV records
GHSA-jjjh-jjxp-wpff

Charts affected

458 by stars
ChartLatestAffected imagesRadar Score
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

19,226
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
jackson-databind@2.12.3
2.12.7.1

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
jackson-databind@2.12.6
2.12.7.1

Open the chart page →

15,675
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
jackson-databind@2.13.4
2.13.4.2

Open the chart page →

8,928
pagesmuthu-pages1.0.01 of 3See more

pages muthu-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
jackson-databind@2.10.4
2.12.7.1

Open the chart page →

9,300
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
adagber/planner:v1.0e5c1ed097752
jackson-databind@2.13.0
2.13.4.2

Open the chart page →

27,721
pagesnarain1.0.01 of 3See more

pages narain 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagesnarasimha-pages1.0.01 of 3See more

pages narasimha-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagesnavin-brixton1.0.01 of 3See more

pages navin-brixton 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
jackson-databind@2.5.0
2.12.7.1

Open the chart page →

55,726
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
jackson-databind@2.10.5.1
2.12.7.1

Open the chart page →

2,640
ma1sdnetsocVerified publisher0.2.11 of 1See more

ma1sd netsoc 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
jackson-databind@2.9.9.1
2.12.7.1

Open the chart page →

3,582
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

3,422
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

5,875
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
jackson-databind@2.10.5.1
2.12.7.1

Open the chart page →

4,547
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
jackson-databind@2.13.3
2.13.4.2

Open the chart page →

5,873
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
jackson-databind@2.10.3
2.12.7.1

Open the chart page →

3,633
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jackson-databind@2.4.0
2.12.7.1

Open the chart page →

8,540
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jackson-databind@2.11.4
2.12.7.1

Open the chart page →

2,421
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
jackson-databind@2.9.5
2.12.7.1

Open the chart page →

63,223
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
jackson-databind@2.7.3
2.12.7.1

Open the chart page →

88,546
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
jackson-databind@2.9.0
2.12.7.1

Open the chart page →

42,614
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
jackson-databind@2.10.2
2.12.7.1

Open the chart page →

12,927
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
jackson-databind@2.7.3
2.12.7.1

Open the chart page →

38,865
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
jackson-databind@2.9.5
2.12.7.1

Open the chart page →

6,350
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
jackson-databind@2.9.6
2.12.7.1
voltha/voltha-onos:5.1.8e038acb950d3
jackson-databind@2.10.0
2.12.7.1

Open the chart page →

41,044
bpjstk-serviceopenshift1.0.04 of 6See more

bpjstk-service openshift 1.0.0

4 of the 6 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
andrianrf/bpjstk-service:latest46abe878d9d8
jackson-databind@2.11.2
2.12.7.1
andrianrf/bpjstk-simulator:latestb63fdb51d39d
jackson-databind@2.11.2
2.12.7.1
andrianrf/iso-client:latestba560086ce15
jackson-databind@2.11.2
2.12.7.1
andrianrf/iso-server:latest7da47f525c7d
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

34,671
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
jackson-databind@2.13.2.2
2.13.4.2

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
jackson-databind@2.13.2.2
2.13.4.2

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
jackson-databind@2.13.2.2
2.13.4.2

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
jackson-databind@2.13.2.2
2.13.4.2

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
jackson-databind@2.13.2.2
2.13.4.2

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
jackson-databind@2.13.2.2
2.13.4.2

Open the chart page →

13,100
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
jackson-databind@2.10.1
2.12.7.1

Open the chart page →

36,215
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
jackson-databind@2.9.9.3
2.12.7.1

Open the chart page →

26,339
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
jackson-databind@2.13.0
2.13.4.2

Open the chart page →

27,537
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
jackson-databind@2.10.0
2.12.7.1

Open the chart page →

19,720
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages-10.1.01 of 1See more

pages pages-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:1.04d2eb25b9225
jackson-databind@2.11.4
2.12.7.1

Open the chart page →

10,392
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-42003.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
jackson-databind@2.11.0
2.12.7.1

Open the chart page →

20,190

Container images carrying it

388 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
wistefan/mvf:lateste0887302b2d8
jackson-databind@2.12.1
2.12.7.1
1
woojoong/wowza:latestec230db19652
jackson-databind@2.9.0
2.12.7.1
1
xeotek/kadeck:4.2.94c6b04d9ce55
jackson-databind@2.13.3
2.13.4.2
1
yuzutech/kroki:0.17.0192b7b27c857
jackson-databind@2.13.1
2.13.4.2
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
jackson-databind@2.10.4
2.12.7.1
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
jackson-databind@2.13.4
2.13.4.2
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
jackson-databind@2.5.3
2.12.7.1
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
jackson-databind@2.10.2
2.12.7.1
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
jackson-databind@2.10.4
2.12.7.1
1
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
jackson-databind@2.10.0
2.12.7.1
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
jackson-databind@2.4.0
2.12.7.1
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
jackson-databind@2.13.2.2
2.13.4.2
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
jackson-databind@2.11.1
2.12.7.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
jackson-databind@2.11.4
2.12.7.1
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
jackson-databind@2.13.4
2.13.4.2
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
jackson-databind@2.9.8
2.12.7.1
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
jackson-databind@2.12.7
2.12.7.1
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
jackson-databind@2.11.4
2.12.7.1
1
ghcr.io/kvaps/linstor-satellite:v1.14.0a573fb9bc809
jackson-databind@2.11.4
2.12.7.1
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
jackson-databind@2.11.0
2.12.7.1
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
jackson-databind@2.4.0
2.12.7.1
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
jackson-databind@2.11.4
2.12.7.1
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
jackson-databind@2.13.4
2.13.4.2
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
jackson-databind@2.9.10
2.12.7.1
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
jackson-databind@2.9.9
2.12.7.1
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
jackson-databind@2.4.0
2.12.7.1
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jackson-databind@2.9.8
2.12.7.1
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
jackson-databind@2.9.8
2.12.7.1
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
jackson-databind@2.12.0
2.12.7.1
1
quay.io/apicurio/apicurio-registry-kube-sync:1.0.170ef31840269
jackson-databind@2.12.5
2.12.7.1
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
jackson-databind@2.13.2.2
2.13.4.2
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
jackson-databind@2.12.4
2.12.7.1
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
jackson-databind@2.12.4
2.12.7.1
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
jackson-databind@2.12.1
2.12.7.1
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
jackson-databind@2.11.4
2.12.7.1
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
jackson-databind@2.13.3
2.13.4.2
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
jackson-databind@2.10.1
2.12.7.1
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
jackson-databind@2.12.3
2.12.7.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.