StackRadar

GHSA-58qw-p7qm-5rvh

Low

Advisory

Published 10 Jul 2023In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.9
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
106
of 17,781 indexed, latest versions
Container images
97
deployed by those charts
Fix available
1 of 1
affected package

Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations

Carried by container images the latest versions of 106 of 17,781 indexed charts deploy, on 97 images.

Affected packageAffected versionsFixed inImages
jetty-xmlmaven7.6.0.v20120127, 8.1.12.v20130726, 8.1.14.v20131031, 8.1.17.v20150415+42 more9.4.52.v20230823, 10.0.16, 11.0.1697
OSV records
GHSA-58qw-p7qm-5rvh

Charts affected

106 by stars
ChartLatestAffected imagesRadar Score
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry GHSA-58qw-p7qm-5rvh.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
jetty-xml@9.4.44.v20210927
9.4.52.v20230823

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry GHSA-58qw-p7qm-5rvh.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
jetty-xml@9.3.24.v20180605
9.4.52.v20230823

Open the chart page →

13,767
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry GHSA-58qw-p7qm-5rvh.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
jetty-xml@9.4.48.v20220622
9.4.52.v20230823

Open the chart page →

18,756
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry GHSA-58qw-p7qm-5rvh.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
jetty-xml@9.4.51.v20230217
9.4.52.v20230823

Open the chart page →

4,240
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry GHSA-58qw-p7qm-5rvh.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
jetty-xml@9.4.12.v20180830
9.4.52.v20230823

Open the chart page →

4,649
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry GHSA-58qw-p7qm-5rvh.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
jetty-xml@9.4.41.v20210516
9.4.52.v20230823

Open the chart page →

9,397

Container images carrying it

97 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
jetty-xml@7.6.0.v20120127
9.4.52.v20230823
4
gradiant/hbase-base:2.0.1a1ee6de94c04
jetty-xml@9.3.19.v20170502
9.4.52.v20230823
4
gchq/hdfs:3.3.35ec58edbb2db
jetty-xml@9.4.43.v20210629
9.4.52.v20230823
3
library/solr:8.11.18c5f7881cebb
jetty-xml@9.4.44.v20210927
9.4.52.v20230823
3
selenium/hub:3.141.5902f251d48d5f
jetty-xml@9.4.12.v20180830
9.4.52.v20230823
3
apache/druid:37.0.00116fb802786
jetty-xml@9.4.43.v20210629
9.4.52.v20230823
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
jetty-xml@9.4.10.v20180503
9.4.52.v20230823
2
dependencytrack/apiserver:4.6.3485ac0952c02
jetty-xml@10.0.12
10.0.16
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
jetty-xml@7.6.0.v20120127
9.4.52.v20230823
2
library/neo4j:4.3.2-enterprise56a9453c4064
jetty-xml@9.4.42.v20210604
9.4.52.v20230823
2
mbentley/omada-controller:4.3f4e682274bed
jetty-xml@9.4.15.v20190215
9.4.52.v20230823
2
rodolpheche/wiremock:2.26.03be08a386092
jetty-xml@9.4.20.v20190813
9.4.52.v20230823
2
5200710/hadoop:3.2.3-java8092d3088a5fb
jetty-xml@9.4.48.v20220622
9.4.52.v20230823
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
jetty-xml@9.4.40.v20210413
9.4.52.v20230823
1
amazon/dynamodb-local:1.20.01ed00881c937
jetty-xml@9.4.48.v20220622
9.4.52.v20230823
1
amazon/dynamodb-local:1.12.08414d80019b0
jetty-xml@8.1.12.v20130726
9.4.52.v20230823
1
apache/drill:1.21.11f96558fd292
jetty-xml@9.4.41.v20210516
9.4.52.v20230823
1
apache/druid:29.0.10cef139b6bf1
jetty-xml@9.4.51.v20230217
9.4.52.v20230823
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jetty-xml@9.4.51.v20230217
9.4.52.v20230823
1
apache/hadoop:3af361b20bec0
jetty-xml@9.4.51.v20230217
9.4.52.v20230823
1
apacheignite/ignite:2.7.0d7deab68b8fa
jetty-xml@9.4.11.v20180605
9.4.52.v20230823
1
apache/iotdb:0.11.28647309f95d1
jetty-xml@9.4.24.v20191120
9.4.52.v20230823
1
apache/iotdb:0.13.3-nodeafa47bf1692a
jetty-xml@9.4.35.v20201120
9.4.52.v20230823
1
apache/nifi-registry:1.14.0090b7f87ec7f
jetty-xml@9.4.42.v20210604
9.4.52.v20230823
1
apache/nifi-registry:0.8.0974efa2f21da
jetty-xml@9.4.19.v20190610
9.4.52.v20230823
1
apachepulsar/pulsar:2.6.14db6ff0b4045
jetty-xml@9.4.29.v20200521
9.4.52.v20230823
1
apimap/api:v1.8.11ae2b3ab00177
jetty-xml@9.4.49.v20220914
9.4.52.v20230823
1
assistiot/cybersecurity-monitoring_ir-thv:latestc8b6c7eaa0cd
jetty-xml@9.4.43.v20210629
9.4.52.v20230823
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
jetty-xml@9.4.43.v20210629
9.4.52.v20230823
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
jetty-xml@9.4.51.v20230217
9.4.52.v20230823
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
jetty-xml@9.4.33.v20201020
9.4.52.v20230823
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
jetty-xml@9.4.33.v20201020
9.4.52.v20230823
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
jetty-xml@9.4.33.v20201020
9.4.52.v20230823
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
jetty-xml@9.4.33.v20201020
9.4.52.v20230823
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
jetty-xml@9.4.33.v20201020
9.4.52.v20230823
1
craigwillis/c2metadata-bd:latestae317d7e4724
jetty-xml@9.4.32.v20200930
9.4.52.v20230823
1
datappeal/hive-metastore:lateste38c085a3567
jetty-xml@9.3.24.v20180605
9.4.52.v20230823
1
dbanda/livy:0.80ca125e68e53
jetty-xml@9.3.24.v20180605
9.4.52.v20230823
1
dbanda/spark:2.4.6d0e6367876ae
jetty-xml@9.3.24.v20180605
9.4.52.v20230823
1
dniel/api-posts:master45a667852f2a
jetty-xml@9.4.25.v20191220
9.4.52.v20230823
1
dremio/dremio-oss:24.1.080ed2e3b7c43
jetty-xml@9.4.51.v20230217
9.4.52.v20230823
1
easypi/openrefine:3.7.0d2950a36a576
jetty-xml@9.4.48.v20220622
9.4.52.v20230823
1
farberg/apache-knox-docker:1.6.14b4a22487394
jetty-xml@9.4.34.v20201102
9.4.52.v20230823
1
fonoster/routr:1.0.0-rc52ca65af17cbc
jetty-xml@9.4.18.v20190429
9.4.52.v20230823
1
gchq/accumulo:2.0.1c460bb587d6d
jetty-xml@9.4.43.v20210629
9.4.52.v20230823
1
gocd/gocd-server:v19.3.02da45cb09d57
jetty-xml@9.4.14.v20181114
9.4.52.v20230823
1
gradiant/hdfs:3.2.2e3bf364fe713
jetty-xml@9.4.20.v20190813
9.4.52.v20230823
1
gradiant/jmxproxy:3.4.045eceb1bc55c
jetty-xml@9.4.8.v20171121
9.4.52.v20230823
1
hazelcast/management-center:5.3.2f9d34300d330
jetty-xml@10.0.15
10.0.16
1
hivemq/hivemq4:dns-4.5.144d194450d48e
jetty-xml@9.4.44.v20210927
9.4.52.v20230823
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.