StackRadar

CVE-2022-45146

Medium

Advisory

Published 21 Nov 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

Garbage collection issue in BC-FJA in Java 13 and later

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
bc-fipsmaven1.0.1, 1.0.2, 1.0.2.1, 1.0.2.31.0.2.417
OSV records
GHSA-68m8-v89j-7j2p

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
bc-fips@1.0.2
1.0.2.4

Open the chart page →

6,556
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.10.0c8f3ebd2a934
bc-fips@1.0.2.3
1.0.2.4

Open the chart page →

10,530
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
bc-fips@1.0.2
1.0.2.4

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
bc-fips@1.0.2
1.0.2.4

Open the chart page →

10,730
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
bc-fips@1.0.2
1.0.2.4

Open the chart page →

38,346
zammaddevplayer0Verified publisher4.0.51 of 4See more

zammad devplayer0 4.0.5

1 of the 4 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
bc-fips@1.0.2
1.0.2.4

Open the chart page →

6,110
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
bc-fips@1.0.2
1.0.2.4

Open the chart page →

17,284
magentomagento3.2.31 of 12See more

magento magento 3.2.3

1 of the 12 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
bc-fips@1.0.2.3
1.0.2.4

Open the chart page →

13,479
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
bc-fips@1.0.2
1.0.2.4

Open the chart page →

31,844
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
bc-fips@1.0.2
1.0.2.4

Open the chart page →

6,045
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
bc-fips@1.0.2.3
1.0.2.4

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
bc-fips@1.0.2.3
1.0.2.4

Open the chart page →

16,975
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.4

Open the chart page →

5,806
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
bc-fips@1.0.2
1.0.2.4

Open the chart page →

10,564
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.1588c2ec10c7f2
bc-fips@1.0.2
1.0.2.4

Open the chart page →

34,754
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
bc-fips@1.0.2.1
1.0.2.4

Open the chart page →

3,064
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bc-fips@1.0.1
1.0.2.4

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.4

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.4

Open the chart page →

10,603
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
bc-fips@1.0.2
1.0.2.4

Open the chart page →

9,300
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-45146.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.4

Open the chart page →

5,806

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
bc-fips@1.0.2
1.0.2.4
2
library/elasticsearch:7.17.35e6ac15bf6a5
bc-fips@1.0.2
1.0.2.4
2
opensearchproject/opensearch:2.1.04254021a8c71
bc-fips@1.0.2.3
1.0.2.4
2
opensearchproject/opensearch:1.1.0967d7f57f72f
bc-fips@1.0.2
1.0.2.4
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
bc-fips@1.0.1
1.0.2.4
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
bc-fips@1.0.2
1.0.2.4
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
bc-fips@1.0.2
1.0.2.4
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
bc-fips@1.0.2
1.0.2.4
1
gluufederation/opendj:4.3.0_011a1128b28b95
bc-fips@1.0.2.1
1.0.2.4
1
library/elasticsearch:7.17.0332c6d416808
bc-fips@1.0.2
1.0.2.4
1
library/elasticsearch:7.17.1588c2ec10c7f2
bc-fips@1.0.2
1.0.2.4
1
library/elasticsearch:7.17.8fdc73b3249c1
bc-fips@1.0.2
1.0.2.4
1
library/sonarqube:10.0.0-communityef9723cf4fe4
bc-fips@1.0.2
1.0.2.4
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
bc-fips@1.0.2.3
1.0.2.4
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
bc-fips@1.0.2.3
1.0.2.4
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
bc-fips@1.0.2
1.0.2.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
bc-fips@1.0.2
1.0.2.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.