StackRadar

CVE-2022-46363

High

Advisory

Published 13 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

Apache CXF vulnerable to Exposure of Sensitive Information

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
cxf-coremaven3.0.3, 3.0.12, 3.1.11, 3.2.2+8 more3.4.1019
OSV records
GHSA-3w37-5p3p-jv92

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
cxf-core@3.4.5
3.4.10

Open the chart page →

7,713
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
cxf-core@3.4.0
3.4.10

Open the chart page →

10,730
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
cxf-core@3.4.5
3.4.10

Open the chart page →

7,713
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
cxf-core@3.4.5
3.4.10

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
cxf-core@3.4.5
3.4.10

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
cxf-core@3.4.0
3.4.10

Open the chart page →

8,866
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
cxf-core@3.4.5
3.4.10

Open the chart page →

13,352
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-core@3.4.0
3.4.10

Open the chart page →

5,806
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
cxf-core@3.4.3
3.4.10

Open the chart page →

18,230
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
cxf-core@3.3.6
3.4.10

Open the chart page →

19,215
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
cxf-core@3.4.5
3.4.10

Open the chart page →

2,887
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
cxf-core@3.2.6
3.4.10

Open the chart page →

27,949
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
cxf-core@3.0.12
3.4.10

Open the chart page →

34,754
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cxf-core@3.2.2
3.4.10

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
cxf-core@3.1.11
3.4.10
ibmcom/microclimate-theia:lateste17bdccc5030
cxf-core@3.1.11
3.4.10

Open the chart page →

57,669
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
cxf-core@3.2.2
3.4.10

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-core@3.4.4
3.4.10

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-core@3.4.4
3.4.10

Open the chart page →

10,603
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
cxf-core@3.0.3
3.4.10

Open the chart page →

6,907
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
cxf-core@3.3.10
3.4.10

Open the chart page →

28,605
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-core@3.4.0
3.4.10

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-46363.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
cxf-core@3.3.7
3.4.10

Open the chart page →

6,213

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
cxf-core@3.4.0
3.4.10
2
opensearchproject/opensearch:2.1.04254021a8c71
cxf-core@3.4.5
3.4.10
2
opensearchproject/opensearch:1.1.0967d7f57f72f
cxf-core@3.4.4
3.4.10
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
cxf-core@3.4.5
3.4.10
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
cxf-core@3.4.3
3.4.10
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
cxf-core@3.2.2
3.4.10
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
cxf-core@3.4.0
3.4.10
1
assistiot/identity-manager_kc:latest0df4b4fa899a
cxf-core@3.4.5
3.4.10
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
cxf-core@3.4.0
3.4.10
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
cxf-core@3.2.2
3.4.10
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
cxf-core@3.1.11
3.4.10
1
ibmcom/microclimate-theia:lateste17bdccc5030
cxf-core@3.1.11
3.4.10
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
cxf-core@3.0.12
3.4.10
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
cxf-core@3.3.7
3.4.10
1
openhab/openhab:3.2.0d0aa4af452c1
cxf-core@3.4.5
3.4.10
1
openkm/openkm-ce:6.3.113bc465a7461b
cxf-core@3.2.6
3.4.10
1
xetusoss/archiva:v2.2.588f25242b9ee
cxf-core@3.0.3
3.4.10
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
cxf-core@3.3.6
3.4.10
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
cxf-core@3.3.10
3.4.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.