StackRadar

CVE-2022-45868

High

Advisory

Published 23 Nov 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
134
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
1 of 1
affected package

Password exposure in H2 Database

Carried by container images the latest versions of 134 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
h2maven1.4.198, 1.4.199, 1.4.200, 2.1.210+2 more2.2.22062
OSV records
GHSA-22wj-vf5f-wrvj

Charts affected

134 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
h2@2.1.214
2.2.220

Open the chart page →

6,556
gocdgocdOfficialVerified publisher2.18.11 of 2See more

gocd gocd 2.18.1

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
gocd/gocd-server:v26.1.0720d1012b93f
h2@1.4.200
2.2.220

Open the chart page →

1,362
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
h2@2.1.214
2.2.220

Open the chart page →

2,503
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
h2@2.1.214
2.2.220

Open the chart page →

1,444
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
h2@1.4.199
2.2.220

Open the chart page →

4,099
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
h2@2.1.214
2.2.220

Open the chart page →

8,636
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
h2@1.4.199
2.2.220
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
h2@1.4.199
2.2.220

Open the chart page →

8,698
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
h2@1.4.200
2.2.220

Open the chart page →

6,711
geoserver-cloudcamptocamp20.0.55 of 11See more

geoserver-cloud camptocamp2 0.0.5

5 of the 11 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
h2@1.4.200
2.2.220

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.65 of 11See more

geoserverCloud camptocamp2 0.0.6

5 of the 11 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
h2@1.4.200
2.2.220

Open the chart page →

84,444
nifi-registrydysnixVerified publisher1.1.51 of 2See more

nifi-registry dysnix 1.1.5

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
apache/nifi-registry:0.8.0974efa2f21da
h2@1.4.199
2.2.220

Open the chart page →

6,531
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
h2@2.1.214
2.2.220

Open the chart page →

37,373
nifi-registryprofyu1.14.0-r0011 of 1See more

nifi-registry profyu 1.14.0-r001

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
apache/nifi-registry:1.14.0090b7f87ec7f
h2@1.4.199
2.2.220

Open the chart page →

4,621
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
h2@1.4.200
2.2.220

Open the chart page →

3,958
pagesalstom-pages-app1.0.01 of 3See more

pages alstom-pages-app 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesandrei-pages1.0.01 of 3See more

pages andrei-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
url-shortenerbeastob1.0.21 of 3See more

url-shortener beastob 1.0.2

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
beastob/url-shortener:1.0.299a49885ab33
h2@1.4.200
2.2.220

Open the chart page →

3,607
pagesberrutig-pages1.0.01 of 3See more

pages berrutig-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesbrian-pages1.0.01 of 3See more

pages brian-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
h2@1.4.200
2.2.220
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
h2@1.4.200
2.2.220

Open the chart page →

88,335
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
h2@2.1.214
2.2.220

Open the chart page →

2,503
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
h2@2.1.214
2.2.220

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
h2@2.1.214
2.2.220

Open the chart page →

6,915
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
h2@1.4.199
2.2.220

Open the chart page →

19,802
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
yaadeencircle360-ossVerified publisher0.2.11 of 1See more

yaade encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
esperotech/yaade:latest24d2d692d948
h2@1.4.200
2.2.220

Open the chart page →

1,000
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
h2@2.1.214
2.2.220

Open the chart page →

9,334
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
h2@1.4.200
2.2.220

Open the chart page →

12,513
canis-majorfiware0.2.31 of 1See more

canis-major fiware 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
h2@1.4.200
2.2.220

Open the chart page →

8,528
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
h2@1.4.200
2.2.220

Open the chart page →

11,835
pagesgary-pages1.0.01 of 3See more

pages gary-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
h2@1.4.200
2.2.220

Open the chart page →

17,702
sharrygeek-cookbookVerified publisher5.4.21 of 1See more

sharry geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
eikek0/sharry:1.8.0661ff3ef42cd
h2@1.4.200
2.2.220

Open the chart page →

1,419
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
h2@1.4.199
2.2.220

Open the chart page →

26,944
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
h2@2.1.212
2.2.220

Open the chart page →

34,754
pageshelm-chart-repos-camden1.0.01 of 3See more

pages helm-chart-repos-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
pageshelm-repo1.0.01 of 3See more

pages helm-repo 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220

Open the chart page →

20,190
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
h2@2.1.212
2.2.220

Open the chart page →

16,401
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2022-45868.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
h2@1.4.200
2.2.220

Open the chart page →

12,856

Container images carrying it

62 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flyway/flyway:6.4.422d97ceb0c47
h2@1.4.200
2.2.220
79
apache/shenyu-admin:2.4.2e8b7c4ddd069
h2@1.4.200
2.2.220
3
dependencytrack/apiserver:4.6.3485ac0952c02
h2@2.1.214
2.2.220
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
h2@1.4.200
2.2.220
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
h2@1.4.200
2.2.220
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
h2@1.4.200
2.2.220
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
h2@1.4.200
2.2.220
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
h2@1.4.200
2.2.220
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
h2@2.1.214
2.2.220
2
andrianrf/bpjstk-service:latest46abe878d9d8
h2@1.4.200
2.2.220
1
andrianrf/iso-client:latestba560086ce15
h2@1.4.200
2.2.220
1
apache/drill:1.21.11f96558fd292
h2@2.1.214
2.2.220
1
apache/nifi-registry:1.14.0090b7f87ec7f
h2@1.4.199
2.2.220
1
apache/nifi-registry:0.8.0974efa2f21da
h2@1.4.199
2.2.220
1
apache/shenyu-admin:2.5.1e2be712fc4f4
h2@1.4.200
2.2.220
1
apache/skywalking-oap-server:9.2.0133d35d2c263
h2@2.1.212
2.2.220
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
h2@1.4.200
2.2.220
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
h2@1.4.200
2.2.220
1
atlassian/bitbucket:10.2.705933f2b1cfd
h2@2.1.214
2.2.220
1
atlassian/confluence-server:7.10.03b9222ab32ef
h2@1.4.200
2.2.220
1
atlassian/jira-software:9.7.264a75aa4ec4e
h2@2.1.214
2.2.220
1
beastob/url-shortener:1.0.299a49885ab33
h2@1.4.200
2.2.220
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
h2@1.4.200
2.2.220
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
h2@2.1.214
2.2.220
1
eikek0/sharry:1.8.0661ff3ef42cd
h2@1.4.200
2.2.220
1
esperotech/yaade:latest24d2d692d948
h2@1.4.200
2.2.220
1
flyway/flyway:9.1545b5d7cdc75a
h2@2.1.214
2.2.220
1
flyway/flyway:9.14.1-alpine80f12c80502b
h2@2.1.214
2.2.220
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
h2@1.4.200
2.2.220
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
h2@1.4.200
2.2.220
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
h2@1.4.200
2.2.220
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
h2@1.4.200
2.2.220
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
h2@1.4.200
2.2.220
1
gocd/gocd-server:v26.1.0720d1012b93f
h2@1.4.200
2.2.220
1
iamdorsah/bastillion:v0.1db83a0254d81
h2@2.1.210
2.2.220
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
h2@2.1.212
2.2.220
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
h2@1.4.199
2.2.220
1
library/sonarqube:8.9.2-community88cd63154d4b
h2@1.4.199
2.2.220
1
library/sonarqube:8.2-communitya246bc64207e
h2@1.4.199
2.2.220
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
h2@1.4.199
2.2.220
1
library/sonarqube:8.9-communityeb2f0be32efd
h2@1.4.199
2.2.220
1
library/sonarqube:10.0.0-communityef9723cf4fe4
h2@2.1.214
2.2.220
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
h2@1.4.199
2.2.220
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
h2@1.4.199
2.2.220
1
owasp/dependency-track:3.8.0efc65e702ee1
h2@1.4.200
2.2.220
1
remche/shinyproxy:2.6.18bcda8a04d3b
h2@1.4.200
2.2.220
1
rundeck/rundeck:3.2.74d64fe56f767
h2@1.4.199
2.2.220
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
h2@1.4.200
2.2.220
1
seataio/seata-server:latest703b5de7f1a6
h2@2.1.214
2.2.220
1
sismics/docs:v1.10f4b0ef019cf1
h2@1.4.199
2.2.220
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.