StackRadar

CVE-2024-47561

Critical

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
97
of 17,781 indexed, latest versions
Container images
90
deployed by those charts
Fix available
1 of 1
affected package

Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)

Carried by container images the latest versions of 97 of 17,781 indexed charts deploy, on 90 images.

Affected packageAffected versionsFixed inImages
avromaven1.7.4, 1.7.6, 1.7.7, 1.8.1+9 more1.11.490
OSV records
GHSA-r7pg-v2c8-mfg3

Charts affected

97 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
avro@1.7.6
1.11.4

Open the chart page →

7,713
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
avro@1.10.2
1.11.4

Open the chart page →

32,259
apicurio-registryapicurio-registry-helmVerified publisher3.8.01 of 2See more

apicurio-registry apicurio-registry-helm 3.8.0

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
avro@1.11.3
1.11.4

Open the chart page →

6,675
druiddruid-helmVerified publisher37.0.21 of 3See more

druid druid-helm 37.0.2

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
apache/druid:37.0.00116fb802786
avro@1.7.7
1.11.4

Open the chart page →

3,812
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
avro@1.7.7
1.11.4

Open the chart page →

5,357
sparkmicrosoft1.0.42 of 3See more

spark microsoft 1.0.4

2 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
dbanda/livy:0.80ca125e68e53
avro@1.7.7
1.11.4
dbanda/spark:2.4.6d0e6367876ae
avro@1.7.7
1.11.4

Open the chart page →

13,738
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
avro@1.7.7
1.11.4

Open the chart page →

12,111
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
avro@1.7.7
1.11.4

Open the chart page →

8,636
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
avro@1.7.7
1.11.4

Open the chart page →

7,930
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
avro@1.11.0
1.11.4

Open the chart page →

10,530
hivebigdata-chartsVerified publisher0.1.81 of 1See more

hive bigdata-charts 0.1.8

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
avro@1.7.7
1.11.4

Open the chart page →

7,166
cloudflowcloudflow-helm-charts0.0.0-NIGHTLY011220201 of 1See more

cloudflow cloudflow-helm-charts 0.0.0-NIGHTLY01122020

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
avro@1.8.2
1.11.4

Open the chart page →

1,886
hdfsdmwm-bigdataVerified publisher1.0.11 of 2See more

hdfs dmwm-bigdata 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
gradiant/hdfs:3.2.2e3bf364fe713
avro@1.7.7
1.11.4

Open the chart page →

7,948
hivedmwm-bigdataVerified publisher0.1.63 of 5See more

hive dmwm-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
avro@1.7.7
1.11.4
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.4
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
avro@1.7.7
1.11.4

Open the chart page →

20,837
hazelcasthazelcastVerified publisher5.10.21 of 2See more

hazelcast hazelcast 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
avro@1.11.3
1.11.4

Open the chart page →

2,634
hive-metastoreheva-helm-chartsVerified publisher0.2.01 of 2See more

hive-metastore heva-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
sslhep/hive-metastore:3.1.39e80af083079
avro@1.8.2
1.11.4

Open the chart page →

7,335
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
avro@1.11.0
1.11.4

Open the chart page →

7,901
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
avro@1.7.7
1.11.4

Open the chart page →

8,198
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
avro@1.8.2
1.11.4

Open the chart page →

7,740
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
avro@1.7.7
1.11.4

Open the chart page →

17,896
hadoopcloudnativeapp1.1.01 of 1See more

hadoop cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
avro@1.7.7
1.11.4

Open the chart page →

5,772
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
avro@1.7.4
1.11.4

Open the chart page →

7,891
hbasedmwm-bigdataVerified publisher0.1.62 of 5See more

hbase dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
avro@1.7.7
1.11.4
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.4

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
avro@1.7.7
1.11.4

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.72 of 6See more

opentsdb dmwm-bigdata 0.1.7

2 of the 6 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
avro@1.7.7
1.11.4
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.4

Open the chart page →

17,511
pitchforkexpediagroup0.1.41 of 1See more

pitchfork expediagroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
expediagroup/pitchfork:1.314f2cf61e7de9
avro@1.10.2
1.11.4

Open the chart page →

3,309
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
avro@1.11.1
1.11.4

Open the chart page →

15,562
hbasegradiant-bigdataVerified publisher0.1.62 of 5See more

hbase gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
gradiant/hbase-base:2.0.1a1ee6de94c04
avro@1.7.7
1.11.4
gradiant/hdfs:2.7.73b28784ba41f
avro@1.7.4
1.11.4

Open the chart page →

13,392
gradle-examplegradle-exampleVerified publisher1.1.31 of 1See more

gradle-example gradle-example 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
avro@1.10.2
1.11.4

Open the chart page →

3,393
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
avro@1.7.7
1.11.4

Open the chart page →

6,165
gridgaingridgainOfficialVerified publisher1.0.61 of 1See more

gridgain gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
gridgain/community:8.9.11d32d182a0e6a
avro@1.7.4
1.11.4

Open the chart page →

4,679
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.01 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
avro@1.11.0
1.11.4

Open the chart page →

14,130
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
avro@1.7.7
1.11.4

Open the chart page →

12,019
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
avro@1.7.7
1.11.4

Open the chart page →

5,772
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
avro@1.11.3
1.11.4

Open the chart page →

1,692
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
avro@1.9.2
1.11.4

Open the chart page →

7,529
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
avro@1.7.7
1.11.4

Open the chart page →

13,486
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
avro@1.9.2
1.11.4

Open the chart page →

15,970
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
avro@1.7.7
1.11.4

Open the chart page →

7,835
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
avro@1.11.0
1.11.4

Open the chart page →

2,326
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
avro@1.7.6
1.11.4

Open the chart page →

7,713
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
avro@1.11.0
1.11.4

Open the chart page →

2,205
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
avro@1.11.1
1.11.4

Open the chart page →

28,131
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
avro@1.10.2
1.11.4

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
avro@1.8.2
1.11.4

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
avro@1.11.1
1.11.4

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
avro@1.10.2
1.11.4

Open the chart page →

13,352
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
avro@1.11.0
1.11.4

Open the chart page →

13,459
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
avro@1.8.1
1.11.4

Open the chart page →

12,018
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47561.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
avro@1.8.2
1.11.4

Open the chart page →

14,066

Container images carrying it

90 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
avro@1.7.7
1.11.4
1
expediagroup/pitchfork:1.314f2cf61e7de9
avro@1.10.2
1.11.4
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
avro@1.8.2
1.11.4
1
gchq/accumulo:2.0.1c460bb587d6d
avro@1.7.7
1.11.4
1
gradiant/hdfs:3.2.2e3bf364fe713
avro@1.7.7
1.11.4
1
gridgain/community:8.9.11d32d182a0e6a
avro@1.7.4
1.11.4
1
hazelcast/hazelcast:5.3.18fe26efde8e1
avro@1.11.1
1.11.4
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
avro@1.11.0
1.11.4
1
hivemq/hivemq4:dns-4.5.144d194450d48e
avro@1.10.1
1.11.4
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
avro@1.8.2
1.11.4
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
avro@1.11.0
1.11.4
1
library/logstash:7.17.817a4f64e9cf5
avro@1.9.2
1.11.4
1
library/storm:2.4.0bd5d420506d6
avro@1.7.7
1.11.4
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
avro@1.8.2
1.11.4
1
lightbend/spark-history-server:2.4.00bedf37f428a
avro@1.8.2
1.11.4
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
avro@1.9.2
1.11.4
1
opensearchproject/data-prepper:2.8.057c25fa01d3c
avro@1.11.3
1.11.4
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
avro@1.11.0
1.11.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
avro@1.7.7
1.11.4
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
avro@1.7.7
1.11.4
1
sslhep/hive-metastore:3.1.39e80af083079
avro@1.8.2
1.11.4
1
trinodb/trino:45038c6f24ab1a4
avro@1.7.7
1.11.4
1
trinodb/trino:405ee80ab5eeab2
avro@1.7.7
1.11.4
1
vitalii1992/analytics-service:latest8e798836ecea
avro@1.11.0
1.11.4
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
avro@1.11.0
1.11.4
1
wavefronthq/proxy:9.2d1064d28f6eb
avro@1.9.2
1.11.4
1
xeotek/kadeck:6.3.439a3b37a17c5
avro@1.11.3
1.11.4
1
xeotek/kadeck:4.2.94c6b04d9ce55
avro@1.11.0
1.11.4
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
avro@1.10.2
1.11.4
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
avro@1.7.7
1.11.4
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
avro@1.7.7
1.11.4
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
avro@1.7.7
1.11.4
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
avro@1.7.7
1.11.4
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
avro@1.11.3
1.11.4
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
avro@1.11.1
1.11.4
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
avro@1.7.7
1.11.4
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
avro@1.7.7
1.11.4
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
avro@1.11.3
1.11.4
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
avro@1.7.6
1.11.4
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
avro@1.10.2
1.11.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.