CVE-2022-48282
HighAdvisory
Published 21 Feb 2023In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.2
- base score, highest
- EPSS
- 0.014
- 71st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 1 of 1
- affected package
MongoDB .NET/C# Driver vulnerable to Deserialization of Untrusted Data
Carried by container images the latest versions of 2 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| MongoDB.Drivernuget | 2.13.1, 2.13.2 | 2.19.0 | 7 |
- OSV records
- GHSA-7j9m-j397-g4wx
Charts affected
2 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| eshoponabpabp-charts | 1.0.0 | 6 of 15See more | 19,799 |
| voice-biometricslumenvox | 2.0.1 | 1 of 26See more | 70,741 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| lumenvox/ | 53decadc102d | MongoDB.Driver | 2.19.0 | 1 |
| ghcr.io/ | 206a9bee17a8 | MongoDB.Driver | 2.19.0 | 1 |
| ghcr.io/ | dd5ce454072e | MongoDB.Driver | 2.19.0 | 1 |
| ghcr.io/ | 7ecb00f53d99 | MongoDB.Driver | 2.19.0 | 1 |
| ghcr.io/ | e53bf47b62d0 | MongoDB.Driver | 2.19.0 | 1 |
| ghcr.io/ | 5e836b17337f | MongoDB.Driver | 2.19.0 | 1 |
| ghcr.io/ | 2ca91145099c | MongoDB.Driver | 2.19.0 | 1 |