StackRadar

CVE-2022-23308

High

Advisory

Published 26 Feb 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.060
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
280
of 17,781 indexed, latest versions
Container images
280
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 280 of 17,781 indexed charts deploy, on 280 images.

Affected packageAffected versionsFixed inImages
libxml2rpm2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8, 2.9.7-9.el8+2 more0:2.9.7-12.el8_5, 2.9.13-1.159
libxml2apk2.9.10-r4, 2.9.10-r5, 2.9.10-r6, 2.9.10-r7+3 more2.9.13-r0124
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+9 more2.9.1+dfsg1-3ubuntu4.13+esm3, 2.9.3+dfsg1-1ubuntu0.7+esm2, 2.9.4+dfsg1-6.1ubuntu1.5, 2.9.10+dfsg-5ubuntu0.20.04.297
OSV records
ALPINE-CVE-2022-23308RHSA-2022:0899UBUNTU-CVE-2022-23308openSUSE-SU-2024:11950-1
Also known as
USN-5324-1, USN-5422-1

Charts affected

280 by stars
ChartLatestAffected imagesRadar Score
sdcsmo-helm-chart6.0.02 of 14See more

sdc smo-helm-chart 6.0.0

2 of the 14 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.13-r0
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.02 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

2 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.13-r0
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.02 of 3See more

sdnc-portal smo-helm-chart 6.0.0

2 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.13-r0
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.02 of 3See more

ueb-listener smo-helm-chart 6.0.0

2 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
dibi/envsubst:latestfc2d92db8024
libxml2@2.9.10-r5
2.9.13-r0
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

25,769
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
libxml2@2.9.7-9.el8_4.2
0:2.9.7-12.el8_5

Open the chart page →

28,165
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-12.el8_5

Open the chart page →

6,671
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.13-r0

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
libxml2@2.9.10-r5
2.9.13-r0

Open the chart page →

3,044
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-12.el8_5

Open the chart page →

6,596
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
libxml2@2.9.10-r4
2.9.13-r0

Open the chart page →

7,480
krokiteochenglim1.0.13 of 5See more

kroki teochenglim 1.0.1

3 of the 5 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.13-r0
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.13-r0
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.13-r0

Open the chart page →

8,715
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.13-r0

Open the chart page →

6,881
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
libxml2@2.9.7-9.el8_4.2
0:2.9.7-12.el8_5

Open the chart page →

12,455
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
libxml2@2.9.10-r4
2.9.13-r0

Open the chart page →

7,510
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2

Open the chart page →

15,330
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
libxml2@2.9.10-r4
2.9.13-r0

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
libxml2@2.9.10-r4
2.9.13-r0

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
libxml2@2.9.10-r4
2.9.13-r0

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
libxml2@2.9.10-r4
2.9.13-r0

Open the chart page →

7,429
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.13-r0

Open the chart page →

1,516
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libxml2@2.9.12-r2
2.9.13-r0

Open the chart page →

1,996
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
libxml2@2.9.7-9.el8_4.2
0:2.9.7-12.el8_5

Open the chart page →

28,605
longhornwenerme1.2.32 of 2See more

longhorn wenerme 1.2.3

2 of the 2 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.13-r0

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-12.el8_5

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-12.el8_5

Open the chart page →

6,138
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.13-r0

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-23308.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.13-r0

Open the chart page →

2,534

Container images carrying it

280 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.2
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.2
1
kanboard/kanboard:v1.2.200b6d33dbbc16
libxml2@2.9.10-r7
2.9.13-r0
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
libxml2@2.9.10-r5
2.9.13-r0
1
kennethreitz/httpbin:latest599fe5e50731
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.5
1
klausmeyer/docker-registry-browser:1.4.0bdc4c6b8595b
libxml2@2.9.12-r1
2.9.13-r0
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
lavandadelpatio/frontend:masterccfc0cd77803
libxml2@2.9.12-r1
2.9.13-r0
1
library/adminer:4.7143ec8cc2f3a
libxml2@2.9.10-r6
2.9.13-r0
1
library/nginx:1.19.3-alpine5aa44b407756
libxml2@2.9.10-r5
2.9.13-r0
1
library/postgres:14.1-alpine578ca5c8452c
libxml2@2.9.12-r2
2.9.13-r0
1
library/postgres:12.3-alpine7693f2082c68
libxml2@2.9.10-r4
2.9.13-r0
1
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.13-r0
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
1
linuxserver/deluge:18.04.10ac871624394
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.5
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.5
1
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.13-r0
1
longhornio/longhorn-ui:v1.1.165560eabe3ee
libxml2@2.9.10-r6
2.9.13-r0
1
lsstsqre/lsp-postgres:latest54283318b16b
libxml2@2.9.10-r4
2.9.13-r0
1
mathnao/certs:1.1.12d38581b447ad
libxml2@2.9.12-r0
2.9.13-r0
1
milesmcc/shynet:v0.12.0e821e31140f7
libxml2@2.9.12-r1
2.9.13-r0
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
libxml2@2.9.7-8.el8
0:2.9.7-12.el8_5
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-12.el8_5
1
minio/operator:v4.1.02adc5be088f5
libxml2@2.9.7-9.el8
0:2.9.7-12.el8_5
1
monogramm/docker-dolibarr:13.0-alpine5afd99523984
libxml2@2.9.10-r7
2.9.13-r0
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm2
1
neilpang/acme.sh:3.0.2595809ad43a2
libxml2@2.9.12-r2
2.9.13-r0
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
libxml2@2.9.10-r5
2.9.13-r0
1
ohif/viewer:latestb4bfecdc7cc6
libxml2@2.9.12-r1
2.9.13-r0
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.5
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm2
1
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm2
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm2
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
libxml2@2.9.3+dfsg1-1ubuntu0.2
2.9.3+dfsg1-1ubuntu0.7+esm2
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
libxml2@2.9.10-r6
2.9.13-r0
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.5
1
opendatacube/restcube:latest91870111837c
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.5
1
opendatacube/wms:latest1b90cdf68831
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.5
1
openelevation/open-elevation:latest82fb21612e86
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.2
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.5
1
opsmx11/issuegen:v2.1.05c50ca123d88
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.