StackRadar

CVE-2024-25062

High

Advisory

Published 4 Feb 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,787 indexed, latest versions
Container images
604
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libxml2 security update

Carried by container images the latest versions of 557 of 17,787 indexed charts deploy, on 604 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+23 more2.9.1+dfsg1-3ubuntu4.13+esm6, 2.9.3+dfsg1-1ubuntu0.7+esm6, 2.9.4+dfsg1-6.1ubuntu1.9+esm1, 2.9.10+dfsg-5ubuntu0.20.04.7+2 more407
libxml2rpm2.9.7-3.25.1, 2.9.7-5.el8, 2.9.7-7.el8, 2.9.7-8.el8+17 more0:2.9.7-13.el8_6.5, 0:2.9.7-16.el8_8.4, 0:2.9.7-18.el8_10.1, 0:2.9.13-6.el9_4+2 more197
OSV records
DEBIAN-CVE-2024-25062RHSA-2024:2679RHSA-2024:3299RHSA-2024:3303RHSA-2024:3626UBUNTU-CVE-2024-25062openSUSE-SU-2024:13676-1RLSA-2024:2679RLSA-2024:3626SUSE-SU-2024:0461-2
Also known as
RHSA-2024:3625, USN-6658-1, USN-6658-2

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
libxml2@2.9.7-8.el8
0:2.9.7-18.el8_10.1

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_10.1

Open the chart page →

6,138
workshop-pipelinesworkshop-pipelines0.1.62 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
libxml2@2.9.7-12.el8_5
0:2.9.7-18.el8_10.1

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2

Open the chart page →

7,673
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
libxml2@2.9.7-15.el8
0:2.9.7-18.el8_10.1

Open the chart page →

6,016
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2024-25062.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1

Open the chart page →

3,697

Container images carrying it

604 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
stackstorm/st2stream:3.81c8904a3bf67
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.7
1
stackstorm/st2timersengine:3.81bf35bfaf00c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.7
1
stackstorm/st2workflowengine:3.819fdfffdbba8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.6
2.9.10+dfsg-5ubuntu0.20.04.7
1
stakater/workshop-operator:v0.0.3897bf456cc97c
libxml2@2.9.7-9.el8_4.2
0:2.9.7-18.el8_10.1
1
stashapp/stash:latest24dbd7607174
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.7
1
statcan/ckan:2.93921305425b8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.7
1
substratusai/verba:v0.4.0-baseURL261695be635eb
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.4
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
sysnet4admin/colosseum-cms:loge74b43c7f492
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
teknas09/bird-pod:latest12a1fa85c4aa
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm6
1
theradius/loggia:0.463ba348546ec
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
thongngo3301/stakefish:latesta341af5976e3
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.4
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libxml2@2.9.13+dfsg-1ubuntu0.2
2.9.13+dfsg-1ubuntu0.4
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm6
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
libxml2@2.9.7-12.el8_5
0:2.9.7-18.el8_10.1
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
libxml2@2.9.7-16.el8_8.1
0:2.9.7-18.el8_10.1
1
vlebediantsev/notes-admin-front:latest007c6670ff48
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
vlebediantsev/notes-project-front:latest945675fd2636
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.7
1
wavefronthq/proxy:9.2d1064d28f6eb
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.9+esm1
1
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.4
1
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.4
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.7
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.4
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm6
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
libxml2@2.9.7-15.el8_7.1
0:2.9.7-18.el8_10.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libxml2@2.9.13+dfsg-1ubuntu0.3
2.9.13+dfsg-1ubuntu0.4
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libxml2@2.9.10+dfsg-5ubuntu0.20.04.5
2.9.10+dfsg-5ubuntu0.20.04.7
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
ghcr.io/cfcontainerizationbot/kubecf-kubectl:v1.19.261daa1bba5cb
libxml2@2.9.7-3.25.1
2.9.7-150000.3.66.1
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libxml2@2.9.14+dfsg-1.3~deb12u1
2.9.14+dfsg-1.3~deb12u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.