StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-io@2.8.0
2.14.0

Open the chart page →

1,995
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
commons-io@2.11.0
2.14.0

Open the chart page →

21,211
mockserverradar-baseVerified publisher5.15.01 of 1See more

mockserver radar-base 5.15.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
commons-io@2.8.0
2.14.0

Open the chart page →

1,257
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
commons-io@2.11.0
2.14.0

Open the chart page →

5,269
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
commons-io@2.5
2.14.0

Open the chart page →

2,855
radar-mockserverradar-baseVerified publisher0.1.31 of 1See more

radar-mockserver radar-base 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
commons-io@2.8.0
2.14.0

Open the chart page →

1,257
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
commons-io@2.11.0
2.14.0

Open the chart page →

951
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
commons-io@2.8.0
2.14.0

Open the chart page →

4,203
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
commons-io@2.5
2.14.0

Open the chart page →

29,227
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
commons-io@2.6
2.14.0
reportportal/service-authorization:5.7.09e73114dbd15
commons-io@2.6
2.14.0

Open the chart page →

25,737
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
commons-io@2.2
2.14.0

Open the chart page →

3,051
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
commons-io@2.8.0
2.14.0

Open the chart page →

6,207
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
commons-io@2.7
2.14.0

Open the chart page →

3,978
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
commons-io@2.7
2.14.0

Open the chart page →

4,245
shenyushenyu0.6.32 of 2See more

shenyu shenyu 0.6.3

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-io@2.11.0
2.14.0
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-io@2.11.0
2.14.0

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
commons-io@2.4
2.14.0

Open the chart page →

12,513
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
commons-io@2.7
2.14.0

Open the chart page →

6,443
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
commons-io@2.11.0
2.14.0

Open the chart page →

4,946
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
commons-io@2.5
2.14.0

Open the chart page →

6,949
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
commons-io@2.4
2.14.0

Open the chart page →

6,907
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
commons-io@2.6
2.14.0

Open the chart page →

3,754
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
commons-io@2.6
2.14.0

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
commons-io@2.6
2.14.0

Open the chart page →

13,079
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
commons-io@2.8.0
2.14.0

Open the chart page →

4,278
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
commons-io@2.11.0
2.14.0

Open the chart page →

1,836
servicexssl-hep1.8.52 of 16See more

servicex ssl-hep 1.8.5

2 of the 16 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder:v1.8.5ab0090083567
commons-io@2.8.0
2.14.0
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
commons-io@2.8.0
2.14.0

Open the chart page →

66,266
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
commons-io@2.6
2.14.0

Open the chart page →

3,164
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
commons-io@2.6
2.14.0

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
commons-io@2.6
2.14.0

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
commons-io@2.6
2.14.0

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
commons-io@2.4
2.14.0

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
commons-io@2.6
2.14.0

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-io@2.8.0
2.14.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-io@2.8.0
2.14.0

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
commons-io@2.11.0
2.14.0

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
commons-io@2.4
2.14.0

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-io@2.6
2.14.0

Open the chart page →

18,756
languagetool-serverszpadel-chartsVerified publisher0.4.01 of 1See more

languagetool-server szpadel-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
commons-io@2.11.0
2.14.0

Open the chart page →

808
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
commons-io@2.8.0
2.14.0

Open the chart page →

4,240
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
commons-io@2.4
2.14.0

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
commons-io@2.11.0
2.14.0
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
commons-io@2.11.0
2.14.0
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
commons-io@2.11.0
2.14.0
thingsboard/tb-node:3.4.1645f43b688f7
commons-io@2.11.0
2.14.0

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
commons-io@2.6
2.14.0

Open the chart page →

12,455
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
commons-io@2.5
2.14.0

Open the chart page →

4,303
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-io@2.4
2.14.0

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-io@2.4
2.14.0

Open the chart page →

3,176
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
commons-io@2.7
2.14.0
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
commons-io@2.11.0
2.14.0

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
commons-io@2.6
2.14.0

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
commons-io@2.8.0
2.14.0

Open the chart page →

28,605
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
commons-io@2.7
2.14.0

Open the chart page →

2,634
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-io@2.3
2.14.0

Open the chart page →

5,806

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
commons-io@2.6
2.14.0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
commons-io@2.11.0
2.14.0
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
commons-io@2.11.0
2.14.0
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
commons-io@2.7
2.14.0
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
commons-io@2.11.0
2.14.0
1
bivas/presto:0.19605545994f806
commons-io@2.4
2.14.0
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-io@2.8.0
2.14.0
1
bluerange/bluerange:26.1.307c8f73b55df
commons-io@2.8.0
2.14.0
1
codetogether/codetogether:latest4348c8a38752
commons-io@2.7
2.14.0
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
commons-io@2.11.0
2.14.0
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
commons-io@2.5
2.14.0
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
commons-io@2.11.0
2.14.0
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-io@2.5
2.14.0
1
craigwillis/c2metadata-bd:latestae317d7e4724
commons-io@2.6
2.14.0
1
datamate/seafile-professional:11.0.202dd66b722464
commons-io@2.11.0
2.14.0
1
datappeal/hive-metastore:lateste38c085a3567
commons-io@2.5
2.14.0
1
dbanda/livy:0.80ca125e68e53
commons-io@2.5
2.14.0
1
dbanda/spark:2.4.6d0e6367876ae
commons-io@2.5
2.14.0
1
deltaio/delta-sharing-server:0.2.08b75118187c5
commons-io@2.4
2.14.0
1
dniel/api-posts:master45a667852f2a
commons-io@2.6
2.14.0
1
dniel/forwardauth:latestf67129ea1c64
commons-io@2.6
2.14.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
commons-io@2.11.0
2.14.0
1
drpcorg/dshackle:0.54.08858fae1859d
commons-io@2.6
2.14.0
1
duck1123/dinsro:latest9568c5961d5d
commons-io@2.10.0
2.14.0
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
commons-io@2.11.0
2.14.0
1
dwimberger/ldap-ad-it:latest0c636e55eb82
commons-io@2.4
2.14.0
1
easypi/openrefine:3.7.0d2950a36a576
commons-io@2.11.0
2.14.0
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
commons-io@2.11.0
2.14.0
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
commons-io@2.5
2.14.0
1
elastictranscoder/media:627e21dc963ab3858c6b
commons-io@2.7
2.14.0
1
elastictranscoder/media-storage:f6d861a026208b8c2359
commons-io@2.7
2.14.0
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
commons-io@2.7
2.14.0
1
emcniece/dockeryourxyzzy:404eccbccc15c
commons-io@2.6
2.14.0
1
emeraldpay/dshackle:0.14.0126f0ae0b388
commons-io@2.6
2.14.0
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
commons-io@2.6
2.14.0
1
expediagroup/pitchfork:1.314f2cf61e7de9
commons-io@2.7
2.14.0
1
farberg/apache-knox-docker:1.6.14b4a22487394
commons-io@2.8.0
2.14.0
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-io@2.4
2.14.0
1
fiware/mintaka:0.7.092a3c5cf43c0
commons-io@2.6
2.14.0
1
fiware/mintaka:latestefc6793388cc
commons-io@2.8.0
2.14.0
1
flofree/base-project:2.1.16b6486c5f81e
commons-io@2.4
2.14.0
1
folioci/mod-codex-ekb:latest235a3fa4adc9
commons-io@2.11.0
2.14.0
1
folioci/mod-codex-inventory:latest6d53ed758fd1
commons-io@2.11.0
2.14.0
1
folioci/mod-codex-mux:latestd4138abfd30d
commons-io@2.11.0
2.14.0
1
folioci/mod-copycat:latest1513fad2b799
commons-io@2.11.0
2.14.0
1
folioci/mod-data-import-converter-storage:latest3028f333778f
commons-io@2.11.0
2.14.0
1
folioci/mod-marccat:latest1b57d690d568
commons-io@2.1
2.14.0
1
fonoster/routr:1.0.0-rc52ca65af17cbc
commons-io@2.2
2.14.0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
commons-io@2.11.0
2.14.0
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
commons-io@2.11.0
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.