StackRadar

CVE-2023-44483

Medium

Advisory

Published 20 Oct 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
58
of 17,781 indexed, latest versions
Container images
51
deployed by those charts
Fix available
1 of 1
affected package

Apache Santuario - XML Security for Java are vulnerable to private key disclosure

Carried by container images the latest versions of 58 of 17,781 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
xmlsecmaven1.5.6, 1.5.8, 2.0.7, 2.0.8+11 more2.2.6, 2.3.4, 3.0.351
OSV records
GHSA-xfrj-6vvc-3xm2

Charts affected

58 by stars
ChartLatestAffected imagesRadar Score
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
xmlsec@1.5.6
2.2.6

Open the chart page →

13,079
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
xmlsec@2.1.5
2.2.6

Open the chart page →

12,455
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
xmlsec@2.1.4
2.2.6

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
xmlsec@2.1.6
2.2.6

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
xmlsec@2.1.5
2.2.6

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
xmlsec@2.2.0
2.2.6

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
xmlsec@2.1.5
2.2.6

Open the chart page →

6,213
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44483.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
xmlsec@2.2.3
2.2.6

Open the chart page →

6,016

Container images carrying it

51 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
xmlsec@2.2.0
2.2.6
2
empathyco/elasticsearch:6.6.2-memlockbcf4365ee7ec
xmlsec@2.0.8
2.2.6
2
library/elasticsearch:7.17.35e6ac15bf6a5
xmlsec@2.1.4
2.2.6
2
metabase/metabase:v0.45.21fb334ce4820
xmlsec@2.3.0
2.3.4
2
opensearchproject/opensearch:2.1.04254021a8c71
xmlsec@2.2.3
2.2.6
2
opensearchproject/opensearch:1.1.0967d7f57f72f
xmlsec@2.2.0
2.2.6
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
xmlsec@2.2.3
2.2.6
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
xmlsec@2.2.3
2.2.6
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
xmlsec@2.2.3
2.2.6
2
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
xmlsec@2.2.3
2.2.6
1
amazon/opendistro-for-elasticsearch:1.4.06df71eb04639
xmlsec@2.0.7
2.2.6
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
xmlsec@2.1.5
2.2.6
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
xmlsec@2.1.5
2.2.6
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
xmlsec@2.2.0
2.2.6
1
assistiot/cybersecurity-monitoring_ir-elk:latest4228b7a8ef40
xmlsec@2.1.4
2.2.6
1
assistiot/identity-manager_kc:latest0df4b4fa899a
xmlsec@2.2.3
2.2.6
1
atlassian/confluence-server:7.10.03b9222ab32ef
xmlsec@2.0.7
2.2.6
1
atlassian/jira-software:8.14.037bc46cbec1a
xmlsec@1.5.6
2.2.6
1
atlassian/jira-software:9.7.264a75aa4ec4e
xmlsec@2.3.2
2.3.4
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
xmlsec@2.2.3
2.2.6
1
datamate/seafile-professional:11.0.202dd66b722464
xmlsec@3.0.0
3.0.3
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
xmlsec@2.1.4
2.2.6
1
farberg/apache-knox-docker:1.6.14b4a22487394
xmlsec@2.1.5
2.2.6
1
graviteeio/am-gateway:4.12.607b7f6dc267a
xmlsec@2.1.4
2.2.6
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
xmlsec@2.1.4
2.2.6
1
hazelcast/management-center:5.3.2f9d34300d330
xmlsec@2.3.0
2.3.4
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
xmlsec@2.0.7
2.2.6
1
library/elasticsearch:7.17.0332c6d416808
xmlsec@2.1.4
2.2.6
1
library/elasticsearch:7.17.1588c2ec10c7f2
xmlsec@2.1.4
2.2.6
1
library/elasticsearch:7.17.8fdc73b3249c1
xmlsec@2.1.4
2.2.6
1
library/sonarqube:10.7.0-community0842dcd4c8f8
xmlsec@2.2.3
2.2.6
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
xmlsec@2.1.4
2.2.6
1
library/sonarqube:8.9.2-community88cd63154d4b
xmlsec@2.1.4
2.2.6
1
library/sonarqube:8.2-communitya246bc64207e
xmlsec@2.1.4
2.2.6
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
xmlsec@2.1.4
2.2.6
1
library/sonarqube:8.9-communityeb2f0be32efd
xmlsec@2.2.3
2.2.6
1
library/sonarqube:10.0.0-communityef9723cf4fe4
xmlsec@2.1.4
2.2.6
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
xmlsec@2.2.3
2.2.6
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
xmlsec@2.1.5
2.2.6
1
metabase/metabase:v0.46.09ebdc664a6b2
xmlsec@3.0.1
3.0.3
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
xmlsec@2.3.3
2.3.4
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
xmlsec@3.0.2
3.0.3
1
remche/shinyproxy:2.6.18bcda8a04d3b
xmlsec@1.5.8
2.2.6
1
reportportal/service-authorization:5.7.09e73114dbd15
xmlsec@2.1.5
2.2.6
1
sonatype/nexus3:3.58.1586060431b64
xmlsec@2.3.0
2.3.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
xmlsec@2.1.4
2.2.6
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
xmlsec@2.1.4
2.2.6
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
xmlsec@2.1.6
2.2.6
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
xmlsec@2.2.3
2.2.6
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
xmlsec@2.2.3
2.2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.