StackRadar

CVE-2023-5072

High

Advisory

Published 14 Nov 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
72nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
71
of 17,781 indexed, latest versions
Container images
74
deployed by those charts
Fix available
1 of 1
affected package

Java: DoS Vulnerability in JSON-JAVA

Carried by container images the latest versions of 71 of 17,781 indexed charts deploy, on 74 images.

Affected packageAffected versionsFixed inImages
jsonmaven20070829, 20140107, 20160212, 20160810+12 more2023101374
OSV records
GHSA-4jq9-2xhw-jpx7

Charts affected

71 by stars
ChartLatestAffected imagesRadar Score
ma1sdnetsocVerified publisher0.2.11 of 1See more

ma1sd netsoc 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
json@20160810
20231013

Open the chart page →

3,582
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
json@20190722
20231013

Open the chart page →

3,633
apicurioone-acre-fundVerified publisher2.3.02 of 5See more

apicurio one-acre-fund 2.3.0

2 of the 5 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
json@20230618
20231013
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
json@20230618
20231013

Open the chart page →

18,667
sentinelopennms-helm-chartsVerified publisher0.4.01 of 2See more

sentinel opennms-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
opennms/sentinel:36.0.288869082a14f
json@20230227
20231013

Open the chart page →

2,024
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
json@20140107
20231013

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
json@20140107
20231013

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
json@20140107
20231013

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
json@20140107
20231013

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
json@20220320
20231013

Open the chart page →

13,455
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
json@20180813
20231013

Open the chart page →

1,995
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
reportportal/service-jobs:5.7.2dc166c58485a
json@20220320
20231013

Open the chart page →

25,737
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
json@20180813
20231013

Open the chart page →

2,209
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
json@20230227
20231013

Open the chart page →

1,597
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
json@20171018
20231013

Open the chart page →

6,949
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
json@20070829
20231013

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
json@20070829
20231013

Open the chart page →

13,079
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
json@20190722
20231013

Open the chart page →

14,493
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
json@20200518
20231013

Open the chart page →

13,767
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
json@20201115
20231013

Open the chart page →

12,455
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
json@20190722
20231013

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-5072.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
json@20180813
20231013

Open the chart page →

5,806

Container images carrying it

74 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
json@20201115
20231013
1
library/sonarqube:8.9-communityeb2f0be32efd
json@20201115
20231013
1
library/sonarqube:10.0.0-communityef9723cf4fe4
json@20220320
20231013
1
linuxserver/unifi-controller:8.0.240ae315a3a456
json@20190722
20231013
1
linuxserver/unifi-controller:7.3.83ab105cc50322
json@20190722
20231013
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
json@20201115
20231013
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
json@20160810
20231013
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
json@20220924
20231013
1
opennms/sentinel:36.0.288869082a14f
json@20230227
20231013
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
json@20230227
20231013
1
owasp/dependency-track:3.8.0efc65e702ee1
json@20190722
20231013
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
json@20210307
20231013
1
reportportal/service-jobs:5.7.2dc166c58485a
json@20220320
20231013
1
rookout/k8s-operator:latest0d083f3ef1a7
json@20180813
20231013
1
thmmniii/fbs-core:v1.27.15438517d9fc2
json@20230618
20231013
1
tock/build_worker:25.10.7080cb6b08d5b
json@20170516
20231013
1
tock/nlp_api:25.10.7c04ffe67b977
json@20170516
20231013
1
trinodb/trino:405ee80ab5eeab2
json@20200518
20231013
1
vromero/activemq-artemis:2.16.0408d6a46b153
json@20171018
20231013
1
wistefan/mvf:lateste0887302b2d8
json@20220924
20231013
1
xeotek/kadeck:4.2.94c6b04d9ce55
json@20220320
20231013
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
json@20180813
20231013
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
json@20171018
20231013
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
json@20220924
20231013
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.