StackRadar

CVE-2023-0842

Medium

Advisory

Published 5 Apr 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
90
of 17,781 indexed, latest versions
Container images
85
deployed by those charts
Fix available
1 of 1
affected package

xml2js is vulnerable to prototype pollution

Carried by container images the latest versions of 90 of 17,781 indexed charts deploy, on 85 images.

Affected packageAffected versionsFixed inImages
xml2jsnpm0.1.14, 0.2.8, 0.4.0, 0.4.16+4 more0.5.085
OSV records
GHSA-776f-qx25-q3cc

Charts affected

90 by stars
ChartLatestAffected imagesRadar Score
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
xml2js@0.4.17
0.5.0

Open the chart page →

4,614
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xml2js@0.4.23
0.5.0

Open the chart page →

22,589
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
xml2js@0.4.19
0.5.0

Open the chart page →

4,667
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
xml2js@0.4.23
0.5.0

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
xml2js@0.4.23
0.5.0

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
xml2js@0.4.19
0.5.0

Open the chart page →

5,410
online-boutiquekubesphere-testVerified publisher0.1.01 of 11See more

online-boutique kubesphere-test 0.1.0

1 of the 11 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
xml2js@0.4.23
0.5.0

Open the chart page →

26,018
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
xml2js@0.4.19
0.5.0

Open the chart page →

3,555
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
xml2js@0.4.19
0.5.0

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
xml2js@0.4.19
0.5.0

Open the chart page →

7,027
iotmmontesVerified publisher0.3.21 of 7See more

iot mmontes 0.3.2

1 of the 7 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
xml2js@0.4.0
0.5.0

Open the chart page →

10,608
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
xml2js@0.4.17
0.5.0

Open the chart page →

7,048
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
xml2js@0.4.23
0.5.0

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
xml2js@0.4.23
0.5.0

Open the chart page →

3,128
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
xml2js@0.4.19
0.5.0

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_server:0.3.31a528c794270
xml2js@0.4.19
0.5.0

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
xml2js@0.2.8
0.5.0

Open the chart page →

27,465
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
xml2js@0.1.14
0.5.0

Open the chart page →

4,219
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
xml2js@0.4.23
0.5.0

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
xml2js@0.4.19
0.5.0

Open the chart page →

6,524
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
xml2js@0.4.23
0.5.0

Open the chart page →

5,215
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
xml2js@0.4.23
0.5.0

Open the chart page →

15,591
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
xml2js@0.4.23
0.5.0

Open the chart page →

7,413
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
xml2js@0.4.23
0.5.0

Open the chart page →

5,582
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xml2js@0.4.23
0.5.0

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
xml2js@0.4.19
0.5.0

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
xml2js@0.4.17
0.5.0

Open the chart page →

3,638
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
xml2js@0.4.19
0.5.0

Open the chart page →

3,143
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xml2js@0.2.8
0.5.0

Open the chart page →

2,638
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
xml2js@0.4.19
0.5.0

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
xml2js@0.4.19
0.5.0

Open the chart page →

29,220
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
xml2js@0.4.23
0.5.0

Open the chart page →

2,267
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
xml2js@0.4.19
0.5.0

Open the chart page →

3,228
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
thingsboard/tb-js-executor:3.4.113e1eadf8ace
xml2js@0.4.23
0.5.0

Open the chart page →

25,394
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
xml2js@0.4.23
0.5.0

Open the chart page →

2,806
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
xml2js@0.4.23
0.5.0

Open the chart page →

5,535
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
xml2js@0.4.19
0.5.0

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
xml2js@0.4.23
0.5.0

Open the chart page →

3,129
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xml2js@0.4.23
0.5.0

Open the chart page →

3,118
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
xml2js@0.4.23
0.5.0

Open the chart page →

5,459

Container images carrying it

85 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
shinobisystems/shinobi:dev3ca746937856
xml2js@0.4.19
0.5.0
1
shinobisystems/shinobi:latestc2f5ce2e1067
xml2js@0.4.19
0.5.0
1
socialmediamacroscope/smile_server:0.3.31a528c794270
xml2js@0.4.19
0.5.0
1
sqlpad/sqlpad:6.7d3d2f430dffd
xml2js@0.4.23
0.5.0
1
stanfordoval/almond-server:latest1a63cdccedaf
xml2js@0.4.23
0.5.0
1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
xml2js@0.4.23
0.5.0
1
subsquid/substrate-explorer:firesquid0889a857f192
xml2js@0.4.23
0.5.0
1
thingsboard/tb-js-executor:3.4.113e1eadf8ace
xml2js@0.4.23
0.5.0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
xml2js@0.4.19
0.5.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
xml2js@0.4.23
0.5.0
1
wazuh/wazuh-dashboard:4.4.11787550d2358
xml2js@0.4.19
0.5.0
1
wekanteam/wekan:v4.2268a51f0327df
xml2js@0.4.17
0.5.0
1
wiremind/scrapoxy:lateste7048929a676
xml2js@0.4.17
0.5.0
1
zooz/predator:1.6f491d1f7a865
xml2js@0.4.19
0.5.0
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
xml2js@0.4.23
0.5.0
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
xml2js@0.4.23
0.5.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
xml2js@0.4.23
0.5.0
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
xml2js@0.4.19
0.5.0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
xml2js@0.4.19
0.5.0
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
xml2js@0.4.19
0.5.0
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
xml2js@0.4.23
0.5.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
xml2js@0.1.14
0.5.0
1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
xml2js@0.4.0
0.5.0
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
xml2js@0.4.23
0.5.0
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
xml2js@0.4.16
0.5.0
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xml2js@0.4.23
0.5.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
xml2js@0.4.23
0.5.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
xml2js@0.2.8
0.5.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
xml2js@0.4.23
0.5.0
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
xml2js@0.4.19
0.5.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
xml2js@0.4.17
0.5.0
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
xml2js@0.4.19
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.