StackRadar

CVE-2022-45688

High

Advisory

Published 13 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
61
deployed by those charts
Fix available
1 of 1
affected package

json stack overflow vulnerability

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 61 images.

Affected packageAffected versionsFixed inImages
jsonmaven20070829, 20140107, 20160212, 20160810+10 more2023022761
OSV records
GHSA-3vqj-43w4-2q58

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
json@20180813
20230227

Open the chart page →

2,209
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
json@20171018
20230227

Open the chart page →

6,949
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
json@20070829
20230227

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
json@20070829
20230227

Open the chart page →

13,079
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
json@20190722
20230227

Open the chart page →

14,493
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
json@20200518
20230227

Open the chart page →

13,767
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
json@20201115
20230227

Open the chart page →

12,455
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
json@20190722
20230227

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-45688.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
json@20180813
20230227

Open the chart page →

5,806

Container images carrying it

61 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
json@20180813
20230227
2
dependencytrack/apiserver:4.6.3485ac0952c02
json@20220924
20230227
2
mbentley/omada-controller:4.3f4e682274bed
json@20180813
20230227
2
opensearchproject/opensearch:2.1.04254021a8c71
json@20180813
20230227
2
opensearchproject/opensearch:1.1.0967d7f57f72f
json@20180813
20230227
2
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
json@20180813
20230227
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
json@20190722
20230227
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
json@20201115
20230227
1
assistiot/automated_configuration:latest23f195a7a26a
json@20201115.0.0
20230227
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
json@20180813
20230227
1
atlassian/confluence-server:7.10.03b9222ab32ef
json@20070829
20230227
1
atlassian/jira-software:8.14.037bc46cbec1a
json@20070829
20230227
1
atlassian/jira-software:9.7.264a75aa4ec4e
json@20070829
20230227
1
biospheere/promcord:latest16d4fd269e66
json@20170516
20230227
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
json@20190722
20230227
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
json@20190722
20230227
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
json@20190722
20230227
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
json@20190722
20230227
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
json@20190722
20230227
1
craigwillis/c2metadata-bd:latestae317d7e4724
json@20190722
20230227
1
dannielkil/book-backend:lateste3b479a55a69
json@20180813
20230227
1
dniel/api-posts:master45a667852f2a
json@20171018
20230227
1
dniel/forwardauth:latestf67129ea1c64
json@20160212
20230227
1
expediagroup/pitchfork:1.314f2cf61e7de9
json@20201115
20230227
1
folioci/mod-marccat:latest1b57d690d568
json@20180813
20230227
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
json@20140107
20230227
1
gotson/komga:0.99.49b15ea6bfc30
json@20171018
20230227
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
json@20140107
20230227
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
json@20140107
20230227
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
json@20140107
20230227
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
json@20140107
20230227
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
json@20220320
20230227
1
hivemq/hivemq4:dns-4.5.144d194450d48e
json@20201115
20230227
1
jacobalberty/unifi:v7.1.664a3616625dda
json@20190722
20230227
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
json@20190722
20230227
1
jacobalberty/unifi:5.10.19c409924e2463
json@20180813
20230227
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
json@20180813
20230227
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
json@20180813
20230227
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
json@20201115
20230227
1
library/sonarqube:8.9.2-community88cd63154d4b
json@20201115
20230227
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
json@20201115
20230227
1
library/sonarqube:8.9-communityeb2f0be32efd
json@20201115
20230227
1
library/sonarqube:10.0.0-communityef9723cf4fe4
json@20220320
20230227
1
linuxserver/unifi-controller:8.0.240ae315a3a456
json@20190722
20230227
1
linuxserver/unifi-controller:7.3.83ab105cc50322
json@20190722
20230227
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
json@20201115
20230227
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
json@20160810
20230227
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
json@20220924
20230227
1
owasp/dependency-track:3.8.0efc65e702ee1
json@20190722
20230227
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
json@20210307
20230227
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.