StackRadar

CVE-2023-0842

Medium

Advisory

Published 5 Apr 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
90
of 17,781 indexed, latest versions
Container images
85
deployed by those charts
Fix available
1 of 1
affected package

xml2js is vulnerable to prototype pollution

Carried by container images the latest versions of 90 of 17,781 indexed charts deploy, on 85 images.

Affected packageAffected versionsFixed inImages
xml2jsnpm0.1.14, 0.2.8, 0.4.0, 0.4.16+4 more0.5.085
OSV records
GHSA-776f-qx25-q3cc

Charts affected

90 by stars
ChartLatestAffected imagesRadar Score
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
xml2js@0.4.19
0.5.0

Open the chart page →

4,431
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
xml2js@0.4.23
0.5.0

Open the chart page →

5,639
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xml2js@0.2.8
0.5.0

Open the chart page →

2,938
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
xml2js@0.4.16
0.5.0

Open the chart page →

14,238
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
xml2js@0.4.23
0.5.0

Open the chart page →

5,251
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
xml2js@0.4.23
0.5.0

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
xml2js@0.1.14
0.5.0

Open the chart page →

5,946
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
xml2js@0.4.23
0.5.0

Open the chart page →

2,521
audiobookshelfgeek-cookbookVerified publisher1.2.21 of 1See more

audiobookshelf geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
xml2js@0.4.23
0.5.0

Open the chart page →

1,959
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
xml2js@0.4.23
0.5.0

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
xml2js@0.4.19
0.5.0

Open the chart page →

7,776
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
xml2js@0.4.16
0.5.0

Open the chart page →

2,702
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xml2js@0.2.8
0.5.0

Open the chart page →

977
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
xml2js@0.4.19
0.5.0

Open the chart page →

2,851
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
xml2js@0.4.23
0.5.0

Open the chart page →

3,925
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
xml2js@0.4.23
0.5.0

Open the chart page →

3,444
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
xml2js@0.4.19
0.5.0

Open the chart page →

1,148
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
xml2js@0.4.23
0.5.0

Open the chart page →

5,079
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
xml2js@0.4.19
0.5.0

Open the chart page →

3,143
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
xml2js@0.4.23
0.5.0

Open the chart page →

31,844
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
xml2js@0.4.19
0.5.0

Open the chart page →

2,823
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
xml2js@0.4.23
0.5.0

Open the chart page →

3,833
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
xml2js@0.4.17
0.5.0

Open the chart page →

2,154
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
xml2js@0.4.23
0.5.0

Open the chart page →

3,820
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
xml2js@0.4.23
0.5.0

Open the chart page →

3,237
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
xml2js@0.4.23
0.5.0

Open the chart page →

4,455
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
xml2js@0.4.23
0.5.0

Open the chart page →

3,071
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
xml2js@0.4.19
0.5.0

Open the chart page →

4,790
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
xml2js@0.4.23
0.5.0

Open the chart page →

5,488
swagger-combine-uicryptexlabsVerified publisher0.2.41 of 1See more

swagger-combine-ui cryptexlabs 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
xml2js@0.4.23
0.5.0

Open the chart page →

1,378
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
xml2js@0.4.19
0.5.0

Open the chart page →

13,852
picolorsealenn0.1.01 of 1See more

picolors ealenn 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ealen/picolors:0.1.03cb01dcbf652
xml2js@0.4.22
0.5.0

Open the chart page →

576
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
xml2js@0.2.8
0.5.0

Open the chart page →

1,755
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
xml2js@0.4.23
0.5.0

Open the chart page →

3,159
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
xml2js@0.4.19
0.5.0

Open the chart page →

1,091
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
xml2js@0.4.17
0.5.0

Open the chart page →

5,941
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
xml2js@0.4.19
0.5.0

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
xml2js@0.4.23
0.5.0

Open the chart page →

4,043
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
xml2js@0.4.23
0.5.0

Open the chart page →

2,102
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
xml2js@0.2.8
0.5.0

Open the chart page →

8,392
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
xml2js@0.4.19
0.5.0

Open the chart page →

4,591
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
xml2js@0.4.23
0.5.0

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
xml2js@0.4.23
0.5.0
governify/registry:v3.4.0d3f37f4f8168
xml2js@0.4.23
0.5.0

Open the chart page →

24,319
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
xml2js@0.4.23
0.5.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
xml2js@0.4.23
0.5.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
xml2js@0.4.23
0.5.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
xml2js@0.4.23
0.5.0

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
xml2js@0.4.23
0.5.0

Open the chart page →

8,213
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
xml2js@0.4.23
0.5.0

Open the chart page →

4,253
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
xml2js@0.4.19
0.5.0

Open the chart page →

4,505
interbtc-hydrainterlay0.1.152 of 4See more

interbtc-hydra interlay 0.1.15

2 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
xml2js@0.4.23
0.5.0
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
xml2js@0.4.23
0.5.0

Open the chart page →

6,831
interlay-firesquidinterlay0.1.112 of 4See more

interlay-firesquid interlay 0.1.11

2 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
xml2js@0.4.23
0.5.0
subsquid/substrate-explorer:firesquid0889a857f192
xml2js@0.4.23
0.5.0

Open the chart page →

4,667
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
xml2js@0.4.23
0.5.0

Open the chart page →

7,232

Container images carrying it

85 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
shinobisystems/shinobi:dev3ca746937856
xml2js@0.4.19
0.5.0
1
shinobisystems/shinobi:latestc2f5ce2e1067
xml2js@0.4.19
0.5.0
1
socialmediamacroscope/smile_server:0.3.31a528c794270
xml2js@0.4.19
0.5.0
1
sqlpad/sqlpad:6.7d3d2f430dffd
xml2js@0.4.23
0.5.0
1
stanfordoval/almond-server:latest1a63cdccedaf
xml2js@0.4.23
0.5.0
1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
xml2js@0.4.23
0.5.0
1
subsquid/substrate-explorer:firesquid0889a857f192
xml2js@0.4.23
0.5.0
1
thingsboard/tb-js-executor:3.4.113e1eadf8ace
xml2js@0.4.23
0.5.0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
xml2js@0.4.19
0.5.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
xml2js@0.4.23
0.5.0
1
wazuh/wazuh-dashboard:4.4.11787550d2358
xml2js@0.4.19
0.5.0
1
wekanteam/wekan:v4.2268a51f0327df
xml2js@0.4.17
0.5.0
1
wiremind/scrapoxy:lateste7048929a676
xml2js@0.4.17
0.5.0
1
zooz/predator:1.6f491d1f7a865
xml2js@0.4.19
0.5.0
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
xml2js@0.4.23
0.5.0
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
xml2js@0.4.23
0.5.0
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
xml2js@0.4.19
0.5.0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
xml2js@0.4.19
0.5.0
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
xml2js@0.4.19
0.5.0
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
xml2js@0.4.23
0.5.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
xml2js@0.1.14
0.5.0
1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
xml2js@0.4.0
0.5.0
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
xml2js@0.4.23
0.5.0
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
xml2js@0.4.16
0.5.0
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xml2js@0.4.23
0.5.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
xml2js@0.4.23
0.5.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
xml2js@0.2.8
0.5.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
xml2js@0.4.23
0.5.0
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
xml2js@0.4.19
0.5.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
xml2js@0.4.17
0.5.0
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
xml2js@0.4.19
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.