StackRadar

CVE-2020-10683

Critical

Advisory

Published 5 Jun 2020In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.073
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

dom4j allows External Entities by default which might enable XXE attacks

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
dom4jmaven1.1, 1.4, 1.6.12.0.321
OSV records
GHSA-hwj3-m3p6-hj38

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
dom4j@1.6.1
2.0.3

Open the chart page →

10,469
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
dom4j@1.6.1
2.0.3

Open the chart page →

11,839
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
dom4j@1.6.1
2.0.3

Open the chart page →

7,891
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
dom4j@1.6.1
2.0.3

Open the chart page →

11,553
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
dom4j@1.6.1
2.0.3

Open the chart page →

11,553
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
dom4j@1.6.1
2.0.3

Open the chart page →

9,722
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
dom4j@1.6.1
2.0.3

Open the chart page →

9,144
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
dom4j@1.6.1
2.0.3

Open the chart page →

23,665
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
dom4j@1.6.1
2.0.3

Open the chart page →

22,442
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
dom4j@1.6.1
2.0.3

Open the chart page →

27,949
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
dom4j@1.6.1
2.0.3

Open the chart page →

6,362
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
dom4j@1.6.1
2.0.3

Open the chart page →

6,451
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
dom4j@1.1
2.0.3
ibmcom/microclimate-theia:lateste17bdccc5030
dom4j@1.6.1
2.0.3

Open the chart page →

57,669
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
dom4j@1.6.1
no fix listed

Open the chart page →

19,295
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
dom4j@1.6.1
2.0.3

Open the chart page →

11,188
datawolfncsaVerified publisher1.1.01 of 3See more

datawolf ncsa 1.1.0

1 of the 3 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
ncsa/datawolf:4.7.0af6649d59150
dom4j@1.6.1
2.0.3

Open the chart page →

4,989
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
dom4j@1.6.1
2.0.3

Open the chart page →

6,907
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
dom4j@1.6.1
2.0.3

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
dom4j@1.4
2.0.3

Open the chart page →

13,079
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
dom4j@1.6.1
2.0.3

Open the chart page →

14,493
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2020-10683.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
dom4j@1.6.1
2.0.3

Open the chart page →

8,554

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mbentley/omada-controller:4.3f4e682274bed
dom4j@1.6.1
2.0.3
2
apacheignite/ignite:2.7.0d7deab68b8fa
dom4j@1.6.1
2.0.3
1
atlassian/confluence-server:7.10.03b9222ab32ef
dom4j@1.6.1
2.0.3
1
atlassian/jira-software:8.14.037bc46cbec1a
dom4j@1.4
2.0.3
1
gocd/gocd-server:v19.3.02da45cb09d57
dom4j@1.6.1
2.0.3
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
dom4j@1.6.1
no fix listed
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
dom4j@1.1
2.0.3
1
ibmcom/microclimate-theia:lateste17bdccc5030
dom4j@1.6.1
2.0.3
1
jacobalberty/unifi:v7.1.664a3616625dda
dom4j@1.6.1
2.0.3
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
dom4j@1.6.1
2.0.3
1
jacobalberty/unifi:5.10.19c409924e2463
dom4j@1.6.1
2.0.3
1
just1not2/streama:1.10.48a2305192dec
dom4j@1.6.1
2.0.3
1
kimb88/hello-world-spring-boot:latest0639155241cb
dom4j@1.6.1
2.0.3
1
linuxserver/unifi-controller:8.0.240ae315a3a456
dom4j@1.6.1
2.0.3
1
linuxserver/unifi-controller:7.3.83ab105cc50322
dom4j@1.6.1
2.0.3
1
ncsa/datawolf:4.7.0af6649d59150
dom4j@1.6.1
2.0.3
1
openkm/openkm-ce:6.3.113bc465a7461b
dom4j@1.6.1
2.0.3
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
dom4j@1.6.1
2.0.3
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
dom4j@1.6.1
2.0.3
1
rundeck/rundeck:3.0.16b13e8059ad72
dom4j@1.6.1
2.0.3
1
xetusoss/archiva:v2.2.588f25242b9ee
dom4j@1.6.1
2.0.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.