StackRadar

CVE-2023-0842

Medium

Advisory

Published 5 Apr 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
90
of 17,781 indexed, latest versions
Container images
85
deployed by those charts
Fix available
1 of 1
affected package

xml2js is vulnerable to prototype pollution

Carried by container images the latest versions of 90 of 17,781 indexed charts deploy, on 85 images.

Affected packageAffected versionsFixed inImages
xml2jsnpm0.1.14, 0.2.8, 0.4.0, 0.4.16+4 more0.5.085
OSV records
GHSA-776f-qx25-q3cc

Charts affected

90 by stars
ChartLatestAffected imagesRadar Score
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
xml2js@0.4.17
0.5.0

Open the chart page →

4,614
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xml2js@0.4.23
0.5.0

Open the chart page →

22,589
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
xml2js@0.4.19
0.5.0

Open the chart page →

4,667
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
xml2js@0.4.23
0.5.0

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
xml2js@0.4.23
0.5.0

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
xml2js@0.4.19
0.5.0

Open the chart page →

5,410
online-boutiquekubesphere-testVerified publisher0.1.01 of 11See more

online-boutique kubesphere-test 0.1.0

1 of the 11 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
xml2js@0.4.23
0.5.0

Open the chart page →

26,018
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
xml2js@0.4.19
0.5.0

Open the chart page →

3,555
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
xml2js@0.4.19
0.5.0

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
xml2js@0.4.19
0.5.0

Open the chart page →

7,027
iotmmontesVerified publisher0.3.21 of 7See more

iot mmontes 0.3.2

1 of the 7 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
xml2js@0.4.0
0.5.0

Open the chart page →

10,608
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
xml2js@0.4.17
0.5.0

Open the chart page →

7,048
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
xml2js@0.4.23
0.5.0

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
xml2js@0.4.23
0.5.0

Open the chart page →

3,128
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
xml2js@0.4.19
0.5.0

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_server:0.3.31a528c794270
xml2js@0.4.19
0.5.0

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
xml2js@0.2.8
0.5.0

Open the chart page →

27,465
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
xml2js@0.1.14
0.5.0

Open the chart page →

4,219
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
xml2js@0.4.23
0.5.0

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
xml2js@0.4.19
0.5.0

Open the chart page →

6,524
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
xml2js@0.4.23
0.5.0

Open the chart page →

5,215
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
xml2js@0.4.23
0.5.0

Open the chart page →

15,591
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
xml2js@0.4.23
0.5.0

Open the chart page →

7,413
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
xml2js@0.4.23
0.5.0

Open the chart page →

5,582
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xml2js@0.4.23
0.5.0

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
xml2js@0.4.19
0.5.0

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
xml2js@0.4.17
0.5.0

Open the chart page →

3,638
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
xml2js@0.4.19
0.5.0

Open the chart page →

3,143
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xml2js@0.2.8
0.5.0

Open the chart page →

2,638
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
xml2js@0.4.19
0.5.0

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
xml2js@0.4.19
0.5.0

Open the chart page →

29,220
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
xml2js@0.4.23
0.5.0

Open the chart page →

2,267
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
xml2js@0.4.19
0.5.0

Open the chart page →

3,228
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
thingsboard/tb-js-executor:3.4.113e1eadf8ace
xml2js@0.4.23
0.5.0

Open the chart page →

25,394
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
xml2js@0.4.23
0.5.0

Open the chart page →

2,806
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
xml2js@0.4.23
0.5.0

Open the chart page →

5,535
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
xml2js@0.4.19
0.5.0

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
xml2js@0.4.23
0.5.0

Open the chart page →

3,129
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xml2js@0.4.23
0.5.0

Open the chart page →

3,118
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2023-0842.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
xml2js@0.4.23
0.5.0

Open the chart page →

5,459

Container images carrying it

85 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
xml2js@0.2.8
0.5.0
3
governify/registry:v3.4.0d3f37f4f8168
xml2js@0.4.23
0.5.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
xml2js@0.4.23
0.5.0
2
mesosphere/kommander:6.100.13917e82333a9
xml2js@0.4.19
0.5.0
2
migmartri/prerender:latest486aacfd5aa9
xml2js@0.4.17
0.5.0
2
outlinewiki/outline:0.69.1d060dcd8f9aa
xml2js@0.4.19
0.5.0
2
requarks/wiki:2:latest68f0d1848261
xml2js@0.4.23
0.5.0
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
xml2js@0.4.19
0.5.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
xml2js@0.4.19
0.5.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
xml2js@0.4.23
0.5.0
2
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
xml2js@0.4.23
0.5.0
1
bnjbvr/kresus:0.22.137e216b182c8
xml2js@0.4.23
0.5.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
xml2js@0.4.23
0.5.0
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
xml2js@0.4.23
0.5.0
1
ealen/picolors:0.1.03cb01dcbf652
xml2js@0.4.22
0.5.0
1
enketo/enketo-express:3.0.4dcad9c2273f6
xml2js@0.4.23
0.5.0
1
fallenbagel/jellyseerr:latest4538137bc5af
xml2js@0.4.19
0.5.0
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
xml2js@0.4.16
0.5.0
1
fiware/idm:8.3.3a1b6ed4ae84f
xml2js@0.4.23
0.5.0
1
folioci/mod-graphql:latestf0655a6a08fd
xml2js@0.4.19
0.5.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
xml2js@0.4.23
0.5.0
1
gristlabs/grist:0.7.96e71b1914a7e
xml2js@0.4.23
0.5.0
1
ianw/quickchart:v1.7.1dc49dd460c37
xml2js@0.4.23
0.5.0
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
xml2js@0.4.23
0.5.0
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
xml2js@0.4.19
0.5.0
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
xml2js@0.4.23
0.5.0
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
xml2js@0.4.23
0.5.0
1
joplin/server:latest3f7b852959aa
xml2js@0.4.23
0.5.0
1
joplin/server:3.0-beta52af57880c0e
xml2js@0.4.23
0.5.0
1
joplin/server:2.14.2-betab87564ef34e9
xml2js@0.4.23
0.5.0
1
linuxserver/codimd:latestb801bbcf6386
xml2js@0.2.8
0.5.0
1
linuxserver/overseerr:1.35.06108ed066d4a
xml2js@0.4.23
0.5.0
1
lissy93/dashy:2.0.51991f7be5ed0
xml2js@0.4.19
0.5.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
xml2js@0.4.23
0.5.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
xml2js@0.4.23
0.5.0
1
misskey/misskey:12.110.1e08b7c478093
xml2js@0.4.23
0.5.0
1
n8nio/n8n:0.212.0a9195bc499a3
xml2js@0.4.19
0.5.0
1
n8nio/n8n:1.33.1dd171d45102a
xml2js@0.4.23
0.5.0
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
xml2js@0.4.23
0.5.0
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
xml2js@0.4.23
0.5.0
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
xml2js@0.4.23
0.5.0
1
nocodb/nocodb:0.258.06779a4ddedf2
xml2js@0.1.14
0.5.0
1
nodered/node-red:2.2.2e131dcadfe92
xml2js@0.4.23
0.5.0
1
nodered/node-red:3.0.2-18e2632a7a35dd
xml2js@0.4.23
0.5.0
1
nodered/node-red-docker:0.19.6-v8070643219ea2
xml2js@0.4.19
0.5.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
xml2js@0.4.23
0.5.0
1
openemr/openemr:6.1.089eaa6d9a4e3
xml2js@0.2.8
0.5.0
1
phntom/codimd:2.4.31b9aafbb62e6
xml2js@0.4.19
0.5.0
1
requarks/wiki:canary-2.5.2438b5865a7386c
xml2js@0.4.23
0.5.0
1
roadiehq/community-backstage-image:latestef355bf5b639
xml2js@0.4.23
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.