StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
commons-io@2.6
2.14.0

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
commons-io@2.0
2.14.0

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
commons-io@2.12.0
2.14.0

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
commons-io@2.11.0
2.14.0

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
commons-io@2.7
2.14.0

Open the chart page →

6,016

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opensearchproject/opensearch:2.15.01963b3ece46d
commons-io@2.8.0
2.14.0
1
opensearchproject/opensearch:2.14.0466a49f379bb
commons-io@2.7
2.14.0
1
opensearchproject/opensearch:2.12.0645d3d9390ad
commons-io@2.8.0
2.14.0
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
commons-io@2.7
2.14.0
1
openwhisk/invoker:1.0.0f5831ec85525
commons-io@2.6
2.14.0
1
owasp/dependency-track:3.8.0efc65e702ee1
commons-io@2.6
2.14.0
1
pcarrascoponce/planner:v1.0981fc482442c
commons-io@2.6
2.14.0
1
pedrocesarti/jmeter-docker:3.314851f144f57
commons-io@2.5
2.14.0
1
penpotapp/exporter:2.2.15c835ffd87ab
commons-io@2.5
2.14.0
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-io@2.8.0
2.14.0
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
commons-io@2.5
2.14.0
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
commons-io@2.5
2.14.0
1
raykrueger/riemann:0.2.14c8baf3de57bb
commons-io@2.5
2.14.0
1
refar/apm-api:v5.7.1241373fa2972
commons-io@2.2
2.14.0
1
remche/shinyproxy:2.6.18bcda8a04d3b
commons-io@2.7
2.14.0
1
reportportal/service-api:5.7.29df41f8fb320
commons-io@2.6
2.14.0
1
reportportal/service-authorization:5.7.09e73114dbd15
commons-io@2.6
2.14.0
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
commons-io@2.11.0
2.14.0
1
rm3l/dev-feed-api:latest9a7f732245a3
commons-io@2.11.0
2.14.0
1
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-io@2.2
2.14.0
1
rundeck/rundeck:3.2.74d64fe56f767
commons-io@2.2
2.14.0
1
rundeck/rundeck:3.0.16b13e8059ad72
commons-io@2.2
2.14.0
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
commons-io@2.7
2.14.0
1
seataio/seata-server:latest703b5de7f1a6
commons-io@2.7
2.14.0
1
seataio/seata-server:1.5.1ee1ed55f4144
commons-io@2.7
2.14.0
1
sismics/docs:v1.10f4b0ef019cf1
commons-io@2.6
2.14.0
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
commons-io@2.4
2.14.0
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
commons-io@2.6
2.14.0
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
commons-io@2.4
2.14.0
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
commons-io@2.8.0
2.14.0
1
sonatype/nexus3:3.58.1586060431b64
commons-io@2.11.0
2.14.0
1
sslhep/hive-metastore:3.1.39e80af083079
commons-io@2.5
2.14.0
1
sslhep/servicex-did-finder:v1.8.5ab0090083567
commons-io@2.8.0
2.14.0
1
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
commons-io@2.8.0
2.14.0
1
structurizr/onpremises:2025.11.094b5ffb5119c8
commons-io@2.8.0
2.14.0
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-io@2.6
2.14.0
1
thehiveproject/cortex:3.1.7f4bc64fb8844
commons-io@2.5
2.14.0
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
commons-io@2.11.0
2.14.0
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
commons-io@2.11.0
2.14.0
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
commons-io@2.11.0
2.14.0
1
thingsboard/tb-node:3.4.1645f43b688f7
commons-io@2.11.0
2.14.0
1
thingsboard/tb-node:3.6.0f40a542832c4
commons-io@2.11.0
2.14.0
1
thmmniii/fbs-core:v1.27.15438517d9fc2
commons-io@2.11.0
2.14.0
1
thmmniii/fbs-runner:v1.27.186105349c1a3
commons-io@2.13.0
2.14.0
1
tock/bot_api:25.10.7dd5d5c70e333
commons-io@2.4
2.14.0
1
tock/kotlin_compiler:25.10.7c9c0fb40089a
commons-io@2.4
2.14.0
1
traccar/traccar:6.7-alpine621c8d6d46fd
commons-io@2.11.0
2.14.0
1
treskon/portrait:DEV-latest88e813f22347
commons-io@2.11.0
2.14.0
1
trinodb/trino:45038c6f24ab1a4
commons-io@2.11.0
2.14.0
1
trinodb/trino:405ee80ab5eeab2
commons-io@2.11.0
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.