StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
commons-io@2.8.0
2.14.0

Open the chart page →

7,713
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
commons-io@2.7
2.14.0

Open the chart page →

1,413
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-io@2.6
2.14.0

Open the chart page →

9,321
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
commons-io@2.6
2.14.0

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
commons-io@2.6
2.14.0

Open the chart page →

3,442
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
commons-io@2.11.0
2.14.0
hazelcast/management-center:5.3.2f9d34300d330
commons-io@2.7
2.14.0

Open the chart page →

28,131
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
commons-io@2.2
2.14.0

Open the chart page →

11,553
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
commons-io@2.5
2.14.0

Open the chart page →

5,277
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-io@2.8.0
2.14.0

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-io@2.4
2.14.0

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
commons-io@2.6
2.14.0

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-io@2.8.0
2.14.0

Open the chart page →

13,352
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-io@2.6
2.14.0

Open the chart page →

7,936
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-io@2.11.0
2.14.0

Open the chart page →

4,145
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
commons-io@2.11.0
2.14.0

Open the chart page →

9,412
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-io@2.8.0
2.14.0

Open the chart page →

9,722
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-io@2.3
2.14.0

Open the chart page →

5,806
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-io@2.8.0
2.14.0

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
commons-io@2.8.0
2.14.0

Open the chart page →

1,816
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-io@2.10.0
2.14.0

Open the chart page →

88,335
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
commons-io@2.8.0
2.14.0

Open the chart page →

1,073
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
commons-io@2.6
2.14.0

Open the chart page →

6,447
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
commons-io@2.6
2.14.0
gocd/gocd-server:v19.3.02da45cb09d57
commons-io@2.6
2.14.0

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
commons-io@2.5
2.14.0

Open the chart page →

4,601
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-io@2.6
2.14.0

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
commons-io@2.4
2.14.0

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
commons-io@2.5
2.14.0

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
commons-io@2.2
2.14.0

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
commons-io@2.4
2.14.0

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
commons-io@2.6
2.14.0

Open the chart page →

22,442
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
commons-io@2.11.0
2.14.0

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-io@2.5
2.14.0
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
commons-io@2.5
2.14.0

Open the chart page →

16,860
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
cp-helm-chartscp-helm-charts0.6.12 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

2 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
commons-io@2.5
2.14.0
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-io@2.5
2.14.0

Open the chart page →

58,857
ldapd4nVerified publisher0.1.01 of 1See more

ldap d4n 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dwimberger/ldap-ad-it:latest0c636e55eb82
commons-io@2.4
2.14.0

Open the chart page →

1,657
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
commons-io@2.5
2.14.0

Open the chart page →

8,245
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-io@2.8.0
2.14.0

Open the chart page →

11,160
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
commons-io@2.4
2.14.0

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
commons-io@2.6
2.14.0

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
commons-io@2.6
2.14.0

Open the chart page →

4,592
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

6,915
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.3.0d4eaa8484246
commons-io@2.4
2.14.0

Open the chart page →

11,174
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
commons-io@2.4
2.14.0

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
commons-io@2.2
2.14.0

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
commons-io@2.6
2.14.0

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
commons-io@2.11.0
2.14.0

Open the chart page →

2,512
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
commons-io@2.6
2.14.0

Open the chart page →

11,482

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
commons-io@2.11.0
2.14.0
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
commons-io@2.6
2.14.0
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
commons-io@2.11.0
2.14.0
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
commons-io@2.11.0
2.14.0
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
commons-io@2.6
2.14.0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
commons-io@2.11.0
2.14.0
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
commons-io@2.11.0
2.14.0
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
commons-io@2.8.0
2.14.0
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
commons-io@2.13.0
2.14.0
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
commons-io@2.7
2.14.0
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
commons-io@2.7
2.14.0
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
commons-io@2.7
2.14.0
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
commons-io@2.6
2.14.0
1
quay.io/newrelic/synthetics-minion:2.2.2198c26e1b8f70
commons-io@2.6
2.14.0
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
commons-io@2.8.0
2.14.0
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
commons-io@2.11.0
2.14.0
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
commons-io@2.11.0
2.14.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
commons-io@2.5
2.14.0
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
commons-io@2.11.0
2.14.0
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
commons-io@2.5
2.14.0
1
quay.io/strimzi/operator:0.45.158c727cd2e68
commons-io@2.11.0
2.14.0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
commons-io@2.6
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.