CVE-2015-6748
MediumAdvisory
Published 13 May 2022In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.022
- 81st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 8
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Improper Neutralization of Input During Web Page Generation in Jsoup
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 8 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jsoupmaven | 1.6.1, 1.7.1, 1.7.2, 1.8.1 | 1.8.3 | 8 |
- OSV records
- GHSA-48rh-qgjr-xfj6
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| kubernetes-loggingkubernetes-logging | 4.8.0 | 1 of 6See more | 10,530 |
| spinnakerdwardu-helm-charts | 2.2.6 | 1 of 2See more | 8,752 |
| riemanncloudnativeapp | 0.1.2 | 1 of 1See more | 6,497 |
| ibm-microclimateibm-charts | 0.1.0 | 1 of 8See more | 57,669 |
| jenkinsjenkins-x | 0.10.38 | 1 of 2See more | 10,682 |
| penpotkubitodevVerified publisher | 1.2.1 | 1 of 5See more | 16,877 |
| polyglotncsaVerified publisher | 0.1.1 | 1 of 18See more | 55,726 |
| archivaslamdev | 0.0.7 | 1 of 2See more | 6,907 |
Container images carrying it
8 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| craigwillis/ | ae317d7e4724 | jsoup | 1.8.3 | 1 |
| ibmcom/ | ab3fd1fdfa18 | jsoup | 1.8.3 | 1 |
| jenkinsci/ | a1f33f004659 | jsoup | 1.8.3 | 1 |
| opensearchproject/ | 43b0cdaf26ed | jsoup | 1.8.3 | 1 |
| penpotapp/ | 5c835ffd87ab | jsoup | 1.8.3 | 1 |
| raykrueger/ | c8baf3de57bb | jsoup | 1.8.3 | 1 |
| xetusoss/ | 88f25242b9ee | jsoup | 1.8.3 | 1 |
| gcr.io/ | 0ee5f968d2ab | jsoup | 1.8.3 | 1 |