StackRadar

CVE-2022-45047

Critical

Advisory

Published 16 Nov 2022In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.036
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
2 of 2
affected packages

Unsafe deserialization in Apache MINA SSHD

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
sshd-coremaven0.14.0, 1.7.0, 2.4.0, 2.6.0+2 more2.9.214
sshd-commonmaven2.3.0, 2.4.0, 2.6.0, 2.7.0+1 more2.9.211
OSV records
GHSA-fhw8-8j55-vwgq

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
sshd-common@2.8.0
sshd-core@2.8.0
2.9.2
2.9.2

Open the chart page →

6,556
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2

Open the chart page →

7,713
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
sshd-common@2.4.0
sshd-core@2.4.0
2.9.2
2.9.2

Open the chart page →

6,531
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
sshd-common@2.7.0
2.9.2

Open the chart page →

37,373
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
sshd-common@2.6.0
sshd-core@2.6.0
2.9.2
2.9.2

Open the chart page →

4,621
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2

Open the chart page →

7,713
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2

Open the chart page →

13,352
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
sshd-core@1.7.0
2.9.2

Open the chart page →

7,936
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
sshd-common@2.7.0
2.9.2

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
sshd-common@2.7.0
2.9.2

Open the chart page →

6,915
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
sshd-core@0.14.0
2.9.2

Open the chart page →

10,682
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
sshd-core@1.7.0
2.9.2

Open the chart page →

12,856
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
sshd-core@0.14.0
2.9.2

Open the chart page →

88,546
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
sshd-core@1.7.0
2.9.2

Open the chart page →

12,927
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
sshd-core@0.14.0
2.9.2

Open the chart page →

38,865
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
sshd-core@1.7.0
2.9.2

Open the chart page →

41,044
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
sshd-common@2.7.0
2.9.2

Open the chart page →

6,443
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2

Open the chart page →

5,856
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
sshd-common@2.3.0
sshd-core@2.4.0
2.9.2
2.9.2

Open the chart page →

28,605
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-45047.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
sshd-common@2.7.0
2.9.2

Open the chart page →

6,016

Container images carrying it

18 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:20.0054ef67eb7da
sshd-common@2.7.0
2.9.2
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2
2
apache/nifi-registry:1.14.0090b7f87ec7f
sshd-common@2.6.0
sshd-core@2.6.0
2.9.2
2.9.2
1
apache/nifi-registry:0.8.0974efa2f21da
sshd-common@2.4.0
sshd-core@2.4.0
2.9.2
2.9.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
sshd-core@1.7.0
2.9.2
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
sshd-common@2.7.0
2.9.2
1
jenkinsci/jenkins:2.67a1f33f004659
sshd-core@0.14.0
2.9.2
1
jhipster/jhipster-registry:latest7184525acd4d
sshd-common@2.7.0
sshd-core@2.7.0
2.9.2
2.9.2
1
library/sonarqube:10.0.0-communityef9723cf4fe4
sshd-common@2.8.0
sshd-core@2.8.0
2.9.2
2.9.2
1
muluder/prograncontrollermcord:0.1.843b597a93da7
sshd-core@0.14.0
2.9.2
1
omecproject/onos-progran:1.0.05715e5648aa0
sshd-core@0.14.0
2.9.2
1
onosproject/onos:2.2.144914a8d4b3f
sshd-core@1.7.0
2.9.2
1
voltha/voltha-onos:5.1.8e038acb950d3
sshd-core@1.7.0
2.9.2
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
sshd-core@1.7.0
2.9.2
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
sshd-common@2.3.0
sshd-core@2.4.0
2.9.2
2.9.2
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
sshd-common@2.7.0
2.9.2
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
sshd-common@2.7.0
2.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.