StackRadar

CVE-2022-42889

Critical

Advisory

Published 13 Oct 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.999
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
51
of 17,781 indexed, latest versions
Container images
50
deployed by those charts
Fix available
1 of 1
affected package

Arbitrary code execution in Apache Commons Text

Carried by container images the latest versions of 51 of 17,781 indexed charts deploy, on 50 images.

Affected packageAffected versionsFixed inImages
commons-textmaven1.5, 1.6, 1.8, 1.91.10.050
OSV records
GHSA-599f-7c49-w659

Charts affected

51 by stars
ChartLatestAffected imagesRadar Score
neo4jneo4j-helm4.3.2-11 of 1See more

neo4j neo4j-helm 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
commons-text@1.9
1.10.0

Open the chart page →

2,640
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
commons-text@1.6
1.10.0

Open the chart page →

6,048
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
commons-text@1.8
1.10.0
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
commons-text@1.8
1.10.0

Open the chart page →

8,698
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
commons-text@1.8
1.10.0

Open the chart page →

4,419
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
commons-text@1.6
1.10.0

Open the chart page →

17,896
geoserver-cloudcamptocamp20.0.53 of 11See more

geoserver-cloud camptocamp2 0.0.5

3 of the 11 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
commons-text@1.6
1.10.0
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
commons-text@1.6
1.10.0
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
commons-text@1.6
1.10.0

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.63 of 11See more

geoserverCloud camptocamp2 0.0.6

3 of the 11 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
commons-text@1.6
1.10.0
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
commons-text@1.6
1.10.0
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
commons-text@1.6
1.10.0

Open the chart page →

84,444
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
commons-text@1.6
1.10.0

Open the chart page →

2,140
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-text@1.6
1.10.0

Open the chart page →

8,752
neo4j-communityequinor-charts1.2.51 of 1See more

neo4j-community equinor-charts 1.2.5

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/neo4j:4.2.4348e3f56faa2
commons-text@1.8
1.10.0

Open the chart page →

2,751
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
commons-text@1.9
1.10.0

Open the chart page →

2,067
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
commons-text@1.8
1.10.0

Open the chart page →

4,621
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
commons-text@1.9
1.10.0

Open the chart page →

9,837
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-text@1.9
1.10.0

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-text@1.6
1.10.0

Open the chart page →

24,930
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-text@1.9
1.10.0

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-text@1.9
1.10.0

Open the chart page →

16,975
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-text@1.9
1.10.0

Open the chart page →

9,722
geoservercamptocamp20.0.33 of 12See more

geoserver camptocamp2 0.0.3

3 of the 12 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-text@1.6
1.10.0
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-text@1.6
1.10.0
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-text@1.6
1.10.0

Open the chart page →

88,335
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
commons-text@1.6
1.10.0

Open the chart page →

9,144
cp-helm-chartscp-helm-charts0.6.11 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

1 of the 8 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-text@1.8
1.10.0

Open the chart page →

58,857
yaadeencircle360-ossVerified publisher0.2.11 of 1See more

yaade encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
esperotech/yaade:latest24d2d692d948
commons-text@1.9
1.10.0

Open the chart page →

1,000
accumulogaffer2.2.11 of 4See more

accumulo gaffer 2.2.1

1 of the 4 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
commons-text@1.6
1.10.0

Open the chart page →

16,892
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-text@1.8
1.10.0

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-text@1.8
1.10.0

Open the chart page →

19,215
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
commons-text@1.9
1.10.0

Open the chart page →

8,943
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
commons-text@1.8
1.10.0

Open the chart page →

12,581
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
commons-text@1.6
1.10.0

Open the chart page →

2,140
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
commons-text@1.9
1.10.0

Open the chart page →

2,653
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
commons-text@1.8
1.10.0

Open the chart page →

4,664
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-text@1.6
1.10.0

Open the chart page →

2,427
neo4jneo4j-helm-old4.3.2-11 of 1See more

neo4j neo4j-helm-old 4.3.2-1

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/neo4j:4.3.2-enterprise56a9453c4064
commons-text@1.9
1.10.0

Open the chart page →

2,640
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
commons-text@1.9
1.10.0

Open the chart page →

5,875
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-text@1.9
1.10.0

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
commons-text@1.9
1.10.0

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
commons-text@1.9
1.10.0

Open the chart page →

5,873
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
commons-text@1.9
1.10.0

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
commons-text@1.9
1.10.0

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
commons-text@1.9
1.10.0

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
commons-text@1.9
1.10.0

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
commons-text@1.9
1.10.0

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
commons-text@1.9
1.10.0

Open the chart page →

13,100
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
commons-text@1.6
1.10.0

Open the chart page →

36,215
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
commons-text@1.9
1.10.0

Open the chart page →

6,237
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
commons-text@1.9
1.10.0

Open the chart page →

25,737
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
commons-text@1.5
1.10.0

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
commons-text@1.6
1.10.0

Open the chart page →

13,079
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
commons-text@1.8
1.10.0

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-text@1.6
1.10.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-text@1.6
1.10.0

Open the chart page →

8,806

Container images carrying it

50 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
commons-text@1.6
1.10.0
3
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
commons-text@1.6
1.10.0
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
commons-text@1.6
1.10.0
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
commons-text@1.6
1.10.0
2
library/neo4j:4.3.2-enterprise56a9453c4064
commons-text@1.9
1.10.0
2
opensearchproject/opensearch:2.1.04254021a8c71
commons-text@1.9
1.10.0
2
rodolpheche/wiremock:2.26.03be08a386092
commons-text@1.6
1.10.0
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-text@1.8
1.10.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-text@1.8
1.10.0
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
commons-text@1.6
1.10.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
commons-text@1.5
1.10.0
1
atlassian/jira-software:8.14.037bc46cbec1a
commons-text@1.6
1.10.0
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-text@1.8
1.10.0
1
esperotech/yaade:latest24d2d692d948
commons-text@1.9
1.10.0
1
farberg/apache-knox-docker:1.6.14b4a22487394
commons-text@1.9
1.10.0
1
gchq/accumulo:2.0.1c460bb587d6d
commons-text@1.6
1.10.0
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-text@1.6
1.10.0
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-text@1.6
1.10.0
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-text@1.6
1.10.0
1
gocd/gocd-server:v19.3.02da45cb09d57
commons-text@1.6
1.10.0
1
gotson/komga:0.99.49b15ea6bfc30
commons-text@1.8
1.10.0
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
commons-text@1.9
1.10.0
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
commons-text@1.9
1.10.0
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
commons-text@1.9
1.10.0
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
commons-text@1.9
1.10.0
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
commons-text@1.9
1.10.0
1
gurolakman/ussigw-core:1.0.48739565c3ea2
commons-text@1.9
1.10.0
1
hivemq/hivemq4:dns-4.5.144d194450d48e
commons-text@1.9
1.10.0
1
housewrecker/gaps:latestf417dd0a7547
commons-text@1.9
1.10.0
1
jacobalberty/unifi:v7.1.664a3616625dda
commons-text@1.8
1.10.0
1
kubebb/gateway-api:v5.6.04d062f20309c
commons-text@1.8
1.10.0
1
library/neo4j:4.2.4348e3f56faa2
commons-text@1.8
1.10.0
1
library/solr:8.7.0d124efd81fbb
commons-text@1.6
1.10.0
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
commons-text@1.8
1.10.0
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
commons-text@1.8
1.10.0
1
liukunup/jmeter:5.59c079617a81b
commons-text@1.9
1.10.0
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
commons-text@1.6
1.10.0
1
openwhisk/invoker:1.0.0f5831ec85525
commons-text@1.6
1.10.0
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-text@1.9
1.10.0
1
reportportal/service-api:5.7.29df41f8fb320
commons-text@1.9
1.10.0
1
rm3l/dev-feed-api:latest9a7f732245a3
commons-text@1.9
1.10.0
1
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-text@1.6
1.10.0
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
commons-text@1.9
1.10.0
1
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-text@1.9
1.10.0
1
vlebediantsev/registration-ms-final:latest427af418b75e
commons-text@1.9
1.10.0
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
commons-text@1.9
1.10.0
1
vromero/activemq-artemis:2.16.0408d6a46b153
commons-text@1.8
1.10.0
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-text@1.6
1.10.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-text@1.8
1.10.0
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-text@1.9
1.10.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.