xetusoss/archiva:v2.2.5 container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of xetusoss/archiva
xetusoss/archiva:v2.2.5 resolved to 88f25242b9ee, scanned 14 Sept 2026: 232 findings, 12 critical, 4 on KEV; deployed by 1 chart, among them archiva.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
138 distinct on this digest
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 88f25242b9ee as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-wfcc-pff6-rgc5 | jetty-server | 9.2.22.v20170606 |
| Medium | GHSA-g5mm-vmx4-3rg7 | spring-context | 5.2.21.RELEASE |
| Medium | GHSA-cf6r-3wgc-h863 | jackson-databind | 2.6.7.3 |
| Medium | ALPINE-CVE-2020-11080 | nghttp2 | 1.35.1-r2 |
| Medium | GHSA-p2v9-g2qv-p635 | netty | no fix listed |
| Medium | GHSA-cmfg-87vq-g5g4 | jackson-databind | 2.6.7.3 |
| Medium | GHSA-x3x3-qwjq-8gj4 | cxf-core | 3.4.10 |
| Medium | GHSA-xfv3-rrfm-f2rv | netty | 3.9.8.Final |
| Medium | GHSA-7vx9-xjhr-rw6h | jetty-server | 9.2.27.v20190403 |
| Medium | ALPINE-CVE-2019-1551 | openssl | 1.1.1d-r2 |
| Medium | GHSA-ccgv-vj62-xf9h | spring-web | no fix listed |
| Medium | GHSA-6fxm-66hq-fc96 | commons-compress | 1.4.1 |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.12.6.1 |
| Medium | ALPINE-CVE-2020-28196 | krb5 | 1.15.5-r1 |
| Medium | ALPINE-CVE-2020-11655 | sqlite | 3.28.0-r3 |
| Medium | GHSA-rpr3-cw39-3pxh | jackson-databind | 2.9.10.4 |
| Medium | GHSA-vw2c-5wph-v92r | cxf-core | 3.0.12 |
| Medium | GHSA-4xr4-4c65-hj7f | tika-core | 1.13 |
| Medium | GHSA-hgg6-8x62-m9gf | cxf-core | 3.0.13 |
| Medium | GHSA-pgf9-h69p-pcgf | spring-core | 4.2.2 |
| Medium | ALPINE-CVE-2020-8231 | curl | 7.66.0-r5 |
| Medium | ALPINE-CVE-2021-23841 | openssl | 1.1.1j-r0 |
| Medium | GHSA-7c2r-3jqf-c9rw | jackson-dataformat-xml | 2.7.8 |
| Medium | GHSA-g3wg-6mcf-8jj6 | jetty-webapp | 9.4.33.v20201020 |
| Medium | ALPINE-CVE-2020-8169 | curl | 7.64.0-r4 |
| Medium | ALPINE-CVE-2020-1971 | openssl | 1.1.1i-r0 |
| Medium | ALPINE-CVE-2019-19244 | sqlite | 3.28.0-r2 |
| Medium | GHSA-hgjh-9rj2-g67j | spring-web | 5.3.33 |
| Medium | GHSA-7r82-7xv7-xcpj | httpclient | 4.5.13 |
| Medium | GHSA-4487-x383-qpph | spring-core | 4.3.15 |
| Medium | GHSA-fh63-4r66-jc7v | velocity-tools | no fix listed |
| Medium | GHSA-wxr5-93ph-8wr9 | commons-beanutils | 1.11.0 |
| Medium | GHSA-8crv-49fr-2h6j | spring-core | 4.3.1 |
| Medium | ALPINE-CVE-2019-16168 | sqlite | 3.28.0-r1 |
| Medium | ALPINE-CVE-2019-2201 | libjpeg-turbo | 1.5.3-r6 |
| Medium | GHSA-3mc7-4q67-w48m | snakeyaml | 1.31 |
| Medium | GHSA-gwrp-pvrq-jmwv | commons-io | 2.7 |
| Medium | GHSA-w6g3-v46q-5p28 | tika-core | 1.19 |
| Medium | GHSA-mvr2-9pj6-7w5j | guava | 24.1.1-android |
| Medium | GHSA-f256-j965-7f32 | netty | no fix listed |
| Medium | ALPINE-CVE-2019-1549 | openssl | 1.1.1d-r0 |
| Medium | GHSA-fh5r-crhr-qrrq | cxf-core | 3.5.10 |
| Medium | GHSA-rcpf-vj53-7h2m | spring-core | 4.3.17 |
| Medium | GHSA-xc67-hjx6-cgg6 | jetty-server | 9.2.28.v20190418 |
| Medium | ALPINE-CVE-2018-14498 | libjpeg-turbo | 1.5.3-r5 |
| Medium | GHSA-hh26-6xwr-ggv7 | spring-beans | 5.2.22.RELEASE |
| Medium | GHSA-9h6p-92jq-888x | jbcrypt | 0.4 |
| Medium | GHSA-qcwq-55hx-v3vh | snappy-java | 1.1.10.1 |
| Medium | GHSA-wx5j-54mm-rqqq | netty | no fix listed |
| Medium | GHSA-7vpq-g998-qpv7 | netty | 3.6.9.Final |