StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
commons-io@2.6
2.14.0

Open the chart page →

11,577
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
commons-io@2.0
2.14.0

Open the chart page →

6,213
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
commons-io@2.12.0
2.14.0

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
commons-io@2.11.0
2.14.0

Open the chart page →

5,846
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
commons-io@2.7
2.14.0

Open the chart page →

6,016

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
vespaengine/vespa:8.526.1569b160f58211
commons-io@2.8.0
2.14.0
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
commons-io@2.6
2.14.0
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
commons-io@2.11.0
2.14.0
1
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-io@2.11.0
2.14.0
1
vlebediantsev/registration-ms-final:latest427af418b75e
commons-io@2.11.0
2.14.0
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
commons-io@2.11.0
2.14.0
1
voltha/voltha-onos:5.1.8e038acb950d3
commons-io@2.11.0
2.14.0
1
vrijbrp/balie:developbc85c89530b9
commons-io@2.11.0
2.14.0
1
vrijbrp/balie-ws:developc6603cb829ea
commons-io@2.11.0
2.14.0
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
commons-io@2.11.0
2.14.0
1
vromero/activemq-artemis:2.16.0408d6a46b153
commons-io@2.2
2.14.0
1
wavefronthq/proxy:9.2d1064d28f6eb
commons-io@2.5
2.14.0
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
commons-io@2.8.0
2.14.0
1
wistefan/mvf:lateste0887302b2d8
commons-io@2.11.0
2.14.0
1
xeotek/kadeck:4.2.94c6b04d9ce55
commons-io@2.11.0
2.14.0
1
xetusoss/archiva:v2.2.588f25242b9ee
commons-io@2.4
2.14.0
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
commons-io@2.12.0
2.14.0
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
commons-io@2.11.0
2.14.0
1
zammad/zammad-docker-compose:zammad-elasticsearch-4.1.0-318274d75a51fc
commons-io@2.6
2.14.0
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-io@2.6
2.14.0
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-io@2.8.0
2.14.0
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
commons-io@2.4
2.14.0
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
commons-io@2.6
2.14.0
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
commons-io@2.11.0
2.14.0
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
commons-io@2.11.0
2.14.0
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
commons-io@2.8.0
2.14.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
commons-io@2.6
2.14.0
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
commons-io@2.5
2.14.0
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
commons-io@2.6
2.14.0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
commons-io@2.8.0
2.14.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-io@2.6
2.14.0
1
ghcr.io/maritimeconnectivity/identityregistry:latest5009fd419742
commons-io@2.11.0
2.14.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
commons-io@2.8.0
2.14.0
1
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
commons-io@2.4
2.14.0
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
commons-io@2.11.0
2.14.0
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
commons-io@2.8.0
2.14.0
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
commons-io@2.5
2.14.0
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
commons-io@2.11.0
2.14.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
commons-io@2.8.0
2.14.0
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
commons-io@2.11.0
2.14.0
1
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-io@2.4
2.14.0
1
ghcr.io/wbstack/queryservice-updater:0.3.84_3.97525a57ac3f1
commons-io@2.4
2.14.0
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
commons-io@2.6
2.14.0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
commons-io@2.8.0
2.14.0
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
commons-io@2.11.0
2.14.0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-io@2.8.0
2.14.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
commons-io@2.6
2.14.0
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
commons-io@2.6
2.14.0
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
commons-io@2.6
2.14.0
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
commons-io@2.11.0
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.