StackRadar

CVE-2024-47072

High

Advisory

Published 7 Nov 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
71
deployed by those charts
Fix available
1 of 1
affected package

XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 71 images.

Affected packageAffected versionsFixed inImages
xstreammaven1.3.1, 1.4.3, 1.4.4, 1.4.7+8 more1.4.2171
OSV records
GHSA-hfq9-hggm-c56q

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
xstream@1.4.18
1.4.21

Open the chart page →

5,856
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
xstream@1.4.13
1.4.21

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
xstream@1.4.11.1
1.4.21

Open the chart page →

13,079
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
xstream@1.3.1
1.4.21

Open the chart page →

11,841
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
xstream@1.4.11.1
1.4.21

Open the chart page →

12,513
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-47072.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
xstream@1.4.20
1.4.21

Open the chart page →

6,016

Container images carrying it

71 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
xstream@1.4.11.1
1.4.21
3
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
xstream@1.4.11.1
1.4.21
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
xstream@1.4.11.1
1.4.21
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
xstream@1.4.11.1
1.4.21
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
xstream@1.4.11.1
1.4.21
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
xstream@1.4.11.1
1.4.21
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
xstream@1.4.11.1
1.4.21
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
xstream@1.4.20
1.4.21
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
xstream@1.4.10
1.4.21
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
xstream@1.4.18
1.4.21
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
xstream@1.4.18
1.4.21
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
xstream@1.4.20
1.4.21
2
apache/shenyu-bootstrap:2.5.11bd5756f6273
xstream@1.4.18
1.4.21
1
atlassian/confluence-server:7.10.03b9222ab32ef
xstream@1.4.13
1.4.21
1
atlassian/crowd:5.2.2ebf761c7d437
xstream@1.4.20
1.4.21
1
atlassian/jira-software:8.14.037bc46cbec1a
xstream@1.4.11.1
1.4.21
1
atlassian/jira-software:9.7.264a75aa4ec4e
xstream@1.4.20
1.4.21
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
xstream@1.4.20
1.4.21
1
choerodon/event-store-service:0.8.03c94c97f6f69
xstream@1.4.9
1.4.21
1
folioci/mod-circulation:latest3eecd2ac2d8a
xstream@1.4.20
1.4.21
1
folioci/mod-marccat:latest1b57d690d568
xstream@1.4.7
1.4.21
1
fonoster/routr:1.0.0-rc52ca65af17cbc
xstream@1.4.9
1.4.21
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
xstream@1.4.11.1
1.4.21
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
xstream@1.4.11.1
1.4.21
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
xstream@1.4.11.1
1.4.21
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
xstream@1.4.11.1
1.4.21
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
xstream@1.4.11.1
1.4.21
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
xstream@1.4.11.1
1.4.21
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
xstream@1.4.11.1
1.4.21
1
graylog2/server:2.4.3-38ff28c66e6c1
xstream@1.4.9
1.4.21
1
hazelcast/hazelcast:3.11.2ca7d5589744f
xstream@1.4.10
1.4.21
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
xstream@1.4.11.1
1.4.21
1
hazelcast/hazelcast-jet:3.0df495e64ea65
xstream@1.4.10
1.4.21
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
xstream@1.4.4
1.4.21
1
ibmcom/microclimate-portal:latested5505e5c7ec
xstream@1.4.10
1.4.21
1
ibmcom/microclimate-theia:lateste17bdccc5030
xstream@1.4.3
1.4.21
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
xstream@1.4.20
1.4.21
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
xstream@1.4.20
1.4.21
1
jhipster/jhipster-registry:latest7184525acd4d
xstream@1.4.18
1.4.21
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
xstream@1.4.11.1
1.4.21
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
xstream@1.4.19
1.4.21
1
library/sonarqube:6.7.6-community0ae5169e3d0f
xstream@1.3.1
1.4.21
1
liukunup/jmeter:5.59c079617a81b
xstream@1.4.19
1.4.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.