StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-io@2.8.0
2.14.0

Open the chart page →

1,995
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
commons-io@2.11.0
2.14.0

Open the chart page →

21,211
mockserverradar-baseVerified publisher5.15.01 of 1See more

mockserver radar-base 5.15.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
commons-io@2.8.0
2.14.0

Open the chart page →

1,257
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
commons-io@2.11.0
2.14.0

Open the chart page →

5,269
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
commons-io@2.5
2.14.0

Open the chart page →

2,855
radar-mockserverradar-baseVerified publisher0.1.31 of 1See more

radar-mockserver radar-base 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
commons-io@2.8.0
2.14.0

Open the chart page →

1,257
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
commons-io@2.11.0
2.14.0

Open the chart page →

951
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
commons-io@2.8.0
2.14.0

Open the chart page →

4,203
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
commons-io@2.5
2.14.0

Open the chart page →

29,227
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
commons-io@2.6
2.14.0
reportportal/service-authorization:5.7.09e73114dbd15
commons-io@2.6
2.14.0

Open the chart page →

25,737
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
commons-io@2.2
2.14.0

Open the chart page →

3,051
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
commons-io@2.8.0
2.14.0

Open the chart page →

6,207
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
commons-io@2.7
2.14.0

Open the chart page →

3,978
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
commons-io@2.7
2.14.0

Open the chart page →

4,245
shenyushenyu0.6.32 of 2See more

shenyu shenyu 0.6.3

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.5.1e2be712fc4f4
commons-io@2.11.0
2.14.0
apache/shenyu-bootstrap:2.5.11bd5756f6273
commons-io@2.11.0
2.14.0

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
commons-io@2.4
2.14.0

Open the chart page →

12,513
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
commons-io@2.7
2.14.0

Open the chart page →

6,443
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
commons-io@2.11.0
2.14.0

Open the chart page →

4,946
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
commons-io@2.5
2.14.0

Open the chart page →

6,949
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
commons-io@2.4
2.14.0

Open the chart page →

6,907
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
commons-io@2.6
2.14.0

Open the chart page →

3,754
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
commons-io@2.6
2.14.0

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
commons-io@2.6
2.14.0

Open the chart page →

13,079
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
commons-io@2.8.0
2.14.0

Open the chart page →

4,278
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
commons-io@2.11.0
2.14.0

Open the chart page →

1,836
servicexssl-hep1.8.52 of 16See more

servicex ssl-hep 1.8.5

2 of the 16 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder:v1.8.5ab0090083567
commons-io@2.8.0
2.14.0
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
commons-io@2.8.0
2.14.0

Open the chart page →

66,266
newrelic-private-minionsstarcher0.1.21 of 1See more

newrelic-private-minion sstarcher 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
commons-io@2.6
2.14.0

Open the chart page →

3,164
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
commons-io@2.6
2.14.0

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
commons-io@2.6
2.14.0

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
commons-io@2.6
2.14.0

Open the chart page →

11,554
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
commons-io@2.4
2.14.0

Open the chart page →

11,841
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
commons-io@2.6
2.14.0

Open the chart page →

14,493
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-io@2.8.0
2.14.0

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
commons-io@2.8.0
2.14.0

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
commons-io@2.11.0
2.14.0

Open the chart page →

13,767
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
commons-io@2.4
2.14.0

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-io@2.6
2.14.0

Open the chart page →

18,756
languagetool-serverszpadel-chartsVerified publisher0.4.01 of 1See more

languagetool-server szpadel-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
commons-io@2.11.0
2.14.0

Open the chart page →

808
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
commons-io@2.8.0
2.14.0

Open the chart page →

4,240
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
commons-io@2.4
2.14.0

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
commons-io@2.11.0
2.14.0
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
commons-io@2.11.0
2.14.0
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
commons-io@2.11.0
2.14.0
thingsboard/tb-node:3.4.1645f43b688f7
commons-io@2.11.0
2.14.0

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
commons-io@2.6
2.14.0

Open the chart page →

12,455
ubooquityvhdirkVerified publisher0.1.31 of 1See more

ubooquity vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
commons-io@2.5
2.14.0

Open the chart page →

4,303
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-io@2.4
2.14.0

Open the chart page →

4,649
queryservice-updaterwbstack0.3.01 of 1See more

queryservice-updater wbstack 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-io@2.4
2.14.0

Open the chart page →

3,176
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
commons-io@2.7
2.14.0
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
commons-io@2.11.0
2.14.0

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
commons-io@2.6
2.14.0

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
commons-io@2.8.0
2.14.0

Open the chart page →

28,605
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
commons-io@2.7
2.14.0

Open the chart page →

2,634
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-io@2.3
2.14.0

Open the chart page →

5,806

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
commons-io@2.8.0
2.14.0
1
lavandadelpatio/tmdb:0.0.2f36af885e915
commons-io@2.2
2.14.0
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
commons-io@2.11.0
2.14.0
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
commons-io@2.4
2.14.0
1
library/logstash:7.17.817a4f64e9cf5
commons-io@2.8.0
2.14.0
1
library/neo4j:4.2.4348e3f56faa2
commons-io@2.7
2.14.0
1
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-io@2.6
2.14.0
1
library/neo4j:3.3.0d4eaa8484246
commons-io@2.4
2.14.0
1
library/solr:8.7.0d124efd81fbb
commons-io@2.8.0
2.14.0
1
library/sonarqube:10.7.0-community0842dcd4c8f8
commons-io@2.8.0
2.14.0
1
library/sonarqube:6.7.6-community0ae5169e3d0f
commons-io@2.4
2.14.0
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
commons-io@2.8.0
2.14.0
1
library/sonarqube:8.9.2-community88cd63154d4b
commons-io@2.8.0
2.14.0
1
library/sonarqube:8.2-communitya246bc64207e
commons-io@2.6
2.14.0
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
commons-io@2.8.0
2.14.0
1
library/sonarqube:8.9-communityeb2f0be32efd
commons-io@2.8.0
2.14.0
1
library/sonarqube:10.0.0-communityef9723cf4fe4
commons-io@2.8.0
2.14.0
1
library/storm:2.4.0bd5d420506d6
commons-io@2.6
2.14.0
1
library/zookeeper:3.43882d9493d38
commons-io@2.6
2.14.0
1
library/zookeeper:3.8-temurin55d1e5b2e601
commons-io@2.11.0
2.14.0
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
commons-io@2.7
2.14.0
1
lightbend/spark-history-server:2.4.00bedf37f428a
commons-io@2.4
2.14.0
1
linuxserver/unifi-controller:8.0.240ae315a3a456
commons-io@2.11.0
2.14.0
1
linuxserver/unifi-controller:7.3.83ab105cc50322
commons-io@2.11.0
2.14.0
1
liukunup/jmeter:5.59c079617a81b
commons-io@2.11.0
2.14.0
1
localstack/localstack:3.19d278167f2b7
commons-io@2.11.0
2.14.0
1
lourdesmorente/new-planner:1.0.0608745878cdb
commons-io@2.6
2.14.0
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
commons-io@2.8.0
2.14.0
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
commons-io@2.11.0
2.14.0
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
commons-io@2.11.0
2.14.0
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
commons-io@2.11.0
2.14.0
1
marcelmay/hadoop-hdfs-fsimage-exporter:1.3abeccb740ef7
commons-io@2.6
2.14.0
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
commons-io@2.0
2.14.0
1
metabase/metabase:v0.46.09ebdc664a6b2
commons-io@2.11.0
2.14.0
1
metabase/metabase:v0.31.2ffb2dccacefc
commons-io@2.5
2.14.0
1
microcks/microcks:0.8.0e3a3e0c67b09
commons-io@2.4
2.14.0
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
commons-io@2.6
2.14.0
1
molynx/planner:v1441c9f52f092
commons-io@2.6
2.14.0
1
muluder/prograncontrollermcord:0.1.843b597a93da7
commons-io@2.2
2.14.0
1
nacos/nacos-server:1.4.1fe6e5688cdf3
commons-io@2.2
2.14.0
1
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
commons-io@2.2
2.14.0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
commons-io@2.11.0
2.14.0
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
commons-io@2.5
2.14.0
1
omecproject/onos-progran:1.0.05715e5648aa0
commons-io@2.2
2.14.0
1
onosproject/onos:2.2.144914a8d4b3f
commons-io@2.6
2.14.0
1
openbas/platform:2.0.5d986d80b0a75
commons-io@2.8.0
2.14.0
1
openhab/openhab:3.2.0d0aa4af452c1
commons-io@2.11.0
2.14.0
1
openkm/openkm-ce:6.3.113bc465a7461b
commons-io@2.4
2.14.0
1
opennms/sentinel:36.0.288869082a14f
commons-io@2.11.0
2.14.0
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
commons-io@2.13.0
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.