CVE-2015-3253
CriticalAdvisory
Published 13 May 2022In the index since 9 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.410
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Groovy
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| groovy-allmaven | 2.2.2 | 2.4.4 | 5 |
- OSV records
- GHSA-qg25-hgjv-cg9q
Charts affected
5 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| smsf-configurationopenshift | 1.0.4 | 1 of 1See more | 13,607 |
| smsf-momtopenshift | 1.0.4 | 1 of 1See more | 13,568 |
| smsf-registrationopenshift | 1.0.4 | 1 of 1See more | 13,551 |
| ussigw-configurationopenshift | 1.0.4 | 1 of 1See more | 13,455 |
| ussigw-coreopenshift | 1.0.4 | 1 of 1See more | 13,100 |
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| gurolakman/ | 9abb3882bcbd | groovy-all | 2.4.4 | 1 |
| gurolakman/ | ce23b20a8a17 | groovy-all | 2.4.4 | 1 |
| gurolakman/ | b22e746edd5d | groovy-all | 2.4.4 | 1 |
| gurolakman/ | bf18525c5ad9 | groovy-all | 2.4.4 | 1 |
| gurolakman/ | 8739565c3ea2 | groovy-all | 2.4.4 | 1 |