StackRadar

CVE-2020-24977

Medium

Advisory

Published 4 Sept 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
182
of 17,781 indexed, latest versions
Container images
170
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 182 of 17,781 indexed charts deploy, on 170 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.9-r0, 2.9.9-r1, 2.9.9-r2, 2.9.9-r3+4 more2.9.9-r3, 2.9.9-r4, 2.9.10-r4, 2.9.10-r583
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+7 more2.9.1+dfsg1-3ubuntu4.13+esm2, 2.9.3+dfsg1-1ubuntu0.7+esm1, 2.9.4+dfsg1-6.1ubuntu1.4, 2.9.10+dfsg-5ubuntu0.20.04.160
libxml2rpm2.9.7-3.22.1, 2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8+1 more0:2.9.7-9.el8, 2.9.7-3.25.1, 2.9.7-lp151.5.15.127
OSV records
ALPINE-CVE-2020-24977RHSA-2021:1597UBUNTU-CVE-2020-24977openSUSE-SU-2020:1430-1SUSE-SU-2020:2612-1
Also known as
USN-4991-1

Charts affected

182 by stars
ChartLatestAffected imagesRadar Score
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
libxml2@2.9.7-7.el8
0:2.9.7-9.el8

Open the chart page →

11,437
static-siteredhat-cop0.0.241 of 2See more

static-site redhat-cop 0.0.24

1 of the 2 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
library/nginx:1.17.9-alpineabe5ce652eb7
libxml2@2.9.9-r3
2.9.9-r4

Open the chart page →

1,726
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,491
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,803
dgbuildersmo-helm-chart6.0.01 of 3See more

dgbuilder smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

28,470
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

24,776
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

29,220
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

24,776
msbsmo-helm-chart6.0.01 of 6See more

msb smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

27,477
multicloudsmo-helm-chart6.0.01 of 14See more

multicloud smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
libxml2@2.9.3+dfsg1-1ubuntu0.2
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

9,436
pndasmo-helm-chart6.0.01 of 3See more

pnda smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

27,477
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

29,220
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

27,477
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

25,769
shinystatcan0.1.31 of 2See more

shiny statcan 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
library/nginx:1.16.0-alpine270bea203d2f
libxml2@2.9.9-r1
2.9.9-r3

Open the chart page →

627
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,480
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
libxml2@2.9.10-r3
2.9.10-r4

Open the chart page →

3,993
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,510
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1

Open the chart page →

15,330
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
libxml2@2.9.10-r4
2.9.10-r5

Open the chart page →

7,429
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-9.el8

Open the chart page →

6,915
nginxwiremindVerified publisher2.1.11 of 1See more

nginx wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2020-24977.

Container imageDigestPackageFixed in
library/nginx:1.17-alpine763e7f0188e3
libxml2@2.9.10-r2
2.9.10-r4

Open the chart page →

966

Container images carrying it

170 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
libxml2@2.9.10-r4
2.9.10-r5
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libxml2@2.9.7-7.el8
0:2.9.7-9.el8
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1
quay.io/eclipse/che-devfile-registry:nightly5d25d47d6e17
libxml2@2.9.10-r4
2.9.10-r5
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
libxml2@2.9.7-7.el8
0:2.9.7-9.el8
1
quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.32.0251e733bf41c
libxml2@2.9.10-r2
2.9.10-r4
1
quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.30.0b312c91d0de6
libxml2@2.9.10-r2
2.9.10-r4
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
libxml2@2.9.7-5.el8
0:2.9.7-9.el8
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
libxml2@2.9.7-8.el8
0:2.9.7-9.el8
1
quay.io/openshift/origin-cli:4.66722d5041b47
libxml2@2.9.7-7.el8
0:2.9.7-9.el8
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
libxml2@2.9.7-7.el8
0:2.9.7-9.el8
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.