StackRadar

CVE-2022-42889

Critical

Advisory

Published 13 Oct 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.999
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
51
of 17,781 indexed, latest versions
Container images
50
deployed by those charts
Fix available
1 of 1
affected package

Arbitrary code execution in Apache Commons Text

Carried by container images the latest versions of 51 of 17,781 indexed charts deploy, on 50 images.

Affected packageAffected versionsFixed inImages
commons-textmaven1.5, 1.6, 1.8, 1.91.10.050
OSV records
GHSA-599f-7c49-w659

Charts affected

51 by stars
ChartLatestAffected imagesRadar Score
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-42889.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
commons-text@1.6
1.10.0

Open the chart page →

6,213

Container images carrying it

50 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
commons-text@1.6
1.10.0
3
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
commons-text@1.6
1.10.0
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
commons-text@1.6
1.10.0
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
commons-text@1.6
1.10.0
2
library/neo4j:4.3.2-enterprise56a9453c4064
commons-text@1.9
1.10.0
2
opensearchproject/opensearch:2.1.04254021a8c71
commons-text@1.9
1.10.0
2
rodolpheche/wiremock:2.26.03be08a386092
commons-text@1.6
1.10.0
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-text@1.8
1.10.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-text@1.8
1.10.0
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
commons-text@1.6
1.10.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
commons-text@1.5
1.10.0
1
atlassian/jira-software:8.14.037bc46cbec1a
commons-text@1.6
1.10.0
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-text@1.8
1.10.0
1
esperotech/yaade:latest24d2d692d948
commons-text@1.9
1.10.0
1
farberg/apache-knox-docker:1.6.14b4a22487394
commons-text@1.9
1.10.0
1
gchq/accumulo:2.0.1c460bb587d6d
commons-text@1.6
1.10.0
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-text@1.6
1.10.0
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-text@1.6
1.10.0
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-text@1.6
1.10.0
1
gocd/gocd-server:v19.3.02da45cb09d57
commons-text@1.6
1.10.0
1
gotson/komga:0.99.49b15ea6bfc30
commons-text@1.8
1.10.0
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
commons-text@1.9
1.10.0
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
commons-text@1.9
1.10.0
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
commons-text@1.9
1.10.0
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
commons-text@1.9
1.10.0
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
commons-text@1.9
1.10.0
1
gurolakman/ussigw-core:1.0.48739565c3ea2
commons-text@1.9
1.10.0
1
hivemq/hivemq4:dns-4.5.144d194450d48e
commons-text@1.9
1.10.0
1
housewrecker/gaps:latestf417dd0a7547
commons-text@1.9
1.10.0
1
jacobalberty/unifi:v7.1.664a3616625dda
commons-text@1.8
1.10.0
1
kubebb/gateway-api:v5.6.04d062f20309c
commons-text@1.8
1.10.0
1
library/neo4j:4.2.4348e3f56faa2
commons-text@1.8
1.10.0
1
library/solr:8.7.0d124efd81fbb
commons-text@1.6
1.10.0
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
commons-text@1.8
1.10.0
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
commons-text@1.8
1.10.0
1
liukunup/jmeter:5.59c079617a81b
commons-text@1.9
1.10.0
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
commons-text@1.6
1.10.0
1
openwhisk/invoker:1.0.0f5831ec85525
commons-text@1.6
1.10.0
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-text@1.9
1.10.0
1
reportportal/service-api:5.7.29df41f8fb320
commons-text@1.9
1.10.0
1
rm3l/dev-feed-api:latest9a7f732245a3
commons-text@1.9
1.10.0
1
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-text@1.6
1.10.0
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
commons-text@1.9
1.10.0
1
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-text@1.9
1.10.0
1
vlebediantsev/registration-ms-final:latest427af418b75e
commons-text@1.9
1.10.0
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
commons-text@1.9
1.10.0
1
vromero/activemq-artemis:2.16.0408d6a46b153
commons-text@1.8
1.10.0
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-text@1.6
1.10.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-text@1.8
1.10.0
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-text@1.9
1.10.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.