StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
commons-io@2.8.0
2.14.0

Open the chart page →

7,713
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
commons-io@2.7
2.14.0

Open the chart page →

1,413
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-io@2.6
2.14.0

Open the chart page →

9,321
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
commons-io@2.6
2.14.0

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
commons-io@2.6
2.14.0

Open the chart page →

3,442
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
commons-io@2.11.0
2.14.0
hazelcast/management-center:5.3.2f9d34300d330
commons-io@2.7
2.14.0

Open the chart page →

28,131
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
commons-io@2.2
2.14.0

Open the chart page →

11,553
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
commons-io@2.5
2.14.0

Open the chart page →

5,277
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-io@2.8.0
2.14.0

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-io@2.4
2.14.0

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
commons-io@2.6
2.14.0

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-io@2.8.0
2.14.0

Open the chart page →

13,352
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-io@2.6
2.14.0

Open the chart page →

7,936
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-io@2.11.0
2.14.0

Open the chart page →

4,145
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
commons-io@2.11.0
2.14.0

Open the chart page →

9,412
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-io@2.8.0
2.14.0

Open the chart page →

9,722
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-io@2.3
2.14.0

Open the chart page →

5,806
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-io@2.8.0
2.14.0

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
commons-io@2.8.0
2.14.0

Open the chart page →

1,816
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-io@2.10.0
2.14.0

Open the chart page →

88,335
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
commons-io@2.8.0
2.14.0

Open the chart page →

1,073
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
commons-io@2.6
2.14.0

Open the chart page →

6,447
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
commons-io@2.6
2.14.0
gocd/gocd-server:v19.3.02da45cb09d57
commons-io@2.6
2.14.0

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
commons-io@2.5
2.14.0

Open the chart page →

4,601
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-io@2.6
2.14.0

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
commons-io@2.4
2.14.0

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
commons-io@2.5
2.14.0

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
commons-io@2.2
2.14.0

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
commons-io@2.4
2.14.0

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
commons-io@2.6
2.14.0

Open the chart page →

22,442
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
commons-io@2.11.0
2.14.0

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-io@2.5
2.14.0
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
commons-io@2.5
2.14.0

Open the chart page →

16,860
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
cp-helm-chartscp-helm-charts0.6.12 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

2 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
commons-io@2.5
2.14.0
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-io@2.5
2.14.0

Open the chart page →

58,857
ldapd4nVerified publisher0.1.01 of 1See more

ldap d4n 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dwimberger/ldap-ad-it:latest0c636e55eb82
commons-io@2.4
2.14.0

Open the chart page →

1,657
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
commons-io@2.5
2.14.0

Open the chart page →

8,245
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-io@2.8.0
2.14.0

Open the chart page →

11,160
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
commons-io@2.4
2.14.0

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
commons-io@2.6
2.14.0

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
commons-io@2.6
2.14.0

Open the chart page →

4,592
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

6,915
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.3.0d4eaa8484246
commons-io@2.4
2.14.0

Open the chart page →

11,174
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
commons-io@2.4
2.14.0

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
commons-io@2.2
2.14.0

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
commons-io@2.6
2.14.0

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
commons-io@2.11.0
2.14.0

Open the chart page →

2,512
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
commons-io@2.6
2.14.0

Open the chart page →

11,482

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airbyte/cron:0.40.17caf4f551c546
commons-io@2.7
2.14.0
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
commons-io@2.6
2.14.0
1
aktosecurity/data-ingestion-service213aded7adc5
commons-io@2.6
2.14.0
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-io@2.6
2.14.0
1
andrianrf/backoffice-be:latest6036614803d4
commons-io@2.11.0
2.14.0
1
andrianrf/iso-server:latest7da47f525c7d
commons-io@2.11.0
2.14.0
1
anguda/ant-media:2.5c435285fc241
commons-io@2.6
2.14.0
1
apache/activemq-artemis:2.37.0bae523439ee3
commons-io@2.11.0
2.14.0
1
apache/bookkeeper:4.14.5a7d9970c148f
commons-io@2.7
2.14.0
1
apache/camel-k:1.10.43bb13d14f64a
commons-io@2.6
2.14.0
1
apache/drill:1.21.11f96558fd292
commons-io@2.7
2.14.0
1
apache/druid:29.0.10cef139b6bf1
commons-io@2.8.0
2.14.0
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
commons-io@2.8.0
2.14.0
1
apache/hadoop:3af361b20bec0
commons-io@2.8.0
2.14.0
1
apacheignite/ignite:2.7.0d7deab68b8fa
commons-io@2.5
2.14.0
1
apache/iotdb:0.11.28647309f95d1
commons-io@2.5
2.14.0
1
apache/iotdb:0.13.3-nodeafa47bf1692a
commons-io@2.11.0
2.14.0
1
apache/nifi-registry:1.14.0090b7f87ec7f
commons-io@2.10.0
2.14.0
1
apache/nifi-registry:0.8.0974efa2f21da
commons-io@2.5
2.14.0
1
apachepinot/pinot:latest-jdk110018bb04ced7
commons-io@2.11.0
2.14.0
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
commons-io@2.8.0
2.14.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
commons-io@2.8.0
2.14.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-io@2.5
2.14.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
commons-io@2.8.0
2.14.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
commons-io@2.8.0
2.14.0
1
apache/ranger:2.7.076c176e8a0e4
commons-io@2.11.0
2.14.0
1
apache/rocketmq:5.3.0434d8398f996
commons-io@2.7
2.14.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-io@2.11.0
2.14.0
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-io@2.11.0
2.14.0
1
apache/skywalking-oap-server:9.2.0133d35d2c263
commons-io@2.7
2.14.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
commons-io@2.6
2.14.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
commons-io@2.6
2.14.0
1
apache/skywalking-ui:8.1.067d50e4deff4
commons-io@2.4
2.14.0
1
apache/tika:2.9.0.092d055a84e9e
commons-io@2.13.0
2.14.0
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
commons-io@2.6
2.14.0
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
commons-io@2.13.0
2.14.0
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
commons-io@2.13.0
2.14.0
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
commons-io@2.11.0
2.14.0
1
arturisimo/planner:v1.0fff9de644941
commons-io@2.6
2.14.0
1
assistiot/automated_configuration:latest23f195a7a26a
commons-io@2.6
2.14.0
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
commons-io@2.3
2.14.0
1
assistiot/cybersecurity-monitoring_ir-ctx:latestae8b3d72eb5d
commons-io@2.5
2.14.0
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
commons-io@2.8.0
2.14.0
1
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-io@2.8.0
2.14.0
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-io@2.6
2.14.0
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-io@2.11.0
2.14.0
1
atlassian/confluence-server:7.10.03b9222ab32ef
commons-io@2.6
2.14.0
1
atlassian/jira-software:8.14.037bc46cbec1a
commons-io@2.6
2.14.0
1
atlassian/jira-software:9.7.264a75aa4ec4e
commons-io@2.8.0
2.14.0
1
atomix/atomix:3.1.127738ff4f5c63
commons-io@2.5
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.