StackRadar

CVE-2024-25062

High

Advisory

Published 4 Feb 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,781 indexed, latest versions
Container images
604
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 557 of 17,781 indexed charts deploy, on 604 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+23 more2.9.1+dfsg1-3ubuntu4.13+esm6, 2.9.3+dfsg1-1ubuntu0.7+esm6, 2.9.4+dfsg1-6.1ubuntu1.9+esm1, 2.9.10+dfsg-5ubuntu0.20.04.7+2 more407
libxml2rpm2.9.7-3.25.1, 2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8+17 more0:2.9.7-13.el8_6.5, 0:2.9.7-16.el8_8.4, 0:2.9.7-18.el8_10.1, 0:2.9.13-6.el9_4+2 more197
OSV records
DEBIAN-CVE-2024-25062RHSA-2024:2679RHSA-2024:3299RHSA-2024:3303RHSA-2024:3626UBUNTU-CVE-2024-25062openSUSE-SU-2024:13676-1RLSA-2024:2679RLSA-2024:3626SUSE-SU-2024:0461-2
Also known as
RHSA-2024:3625, USN-6658-1, USN-6658-2

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-18.el8_10.1

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_10.1

Open the chart page →

6,138
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-18.el8_10.1

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-18.el8_10.1

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1

Open the chart page →

3,697

Container images carrying it

604 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.7
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libxml2@2.9.7-13.el8_6.1
0:2.9.7-13.el8_6.5
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
2
vdiogov/glpi-conteiner:latest6945f84f0058
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
2.9.1+dfsg1-3ubuntu4.13+esm6
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.7
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
libxml2@2.9.7-18.el8_9
0:2.9.7-18.el8_10.1
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
libxml2@2.9.7-12.el8_5
0:2.9.7-18.el8_10.1
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
libxml2@2.9.7-16.el8_8.1
0:2.9.7-16.el8_8.4
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
libxml2@2.9.7-16.el8_8.1
0:2.9.7-16.el8_8.4
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
libxml2@2.9.7-16.el8
0:2.9.7-16.el8_8.4
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
libxml2@2.9.7-9.el8
0:2.9.7-18.el8_10.1
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_10.1
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_10.1
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
libxml2@2.9.7-18.el8_9
0:2.9.7-18.el8_10.1
2
5200710/hadoop:3.2.3-java8092d3088a5fb
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.7
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm1
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.7
1
airbyte/pod-sweeper:1.5.198d2c39d512e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7
1
akaunting/akaunting:3.0.1552811b36ec3a
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u2
1
akeyless/base-rhel:0.0.14ba8900a0061
libxml2@2.9.7-18.el8_9
0:2.9.7-18.el8_10.1
1
allegroai/clearml:2.0.0-613713ae38f7daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.9+esm1
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
libxml2@2.9.7-16.el8
0:2.9.7-16.el8_8.4
1
altinity/metrics-exporter:0.20.01a46d104406d
libxml2@2.9.7-16.el8
0:2.9.7-16.el8_8.4
1
anchore/anchore-engine:v0.10.0bde9eedf639d
libxml2@2.9.7-9.el8
0:2.9.7-18.el8_10.1
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
libxml2@2.9.7-5.el8
0:2.9.7-18.el8_10.1
1
andrianrf/backoffice-be:latest6036614803d4
libxml2@2.9.13-3.el9_1
0:2.9.13-6.el9_4
1
andrianrf/iso-server:latest7da47f525c7d
libxml2@2.9.13-3.el9_1
0:2.9.13-6.el9_4
1
anguda/ant-media:2.5c435285fc241
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.7
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
apache/airflow:2.8.4-python3.964e58748b6b9
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
apache/airflow:2.8.1e5560ad0b86e
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.