StackRadar

CVE-2015-5211

High

Advisory

Published 17 Oct 2018In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.026
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Files or Directories Accessible to External Parties in org.springframework:spring-core

Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
spring-coremaven2.5.6, 2.5.6.SEC03, 3.0.7, 3.0.7.RELEASE+2 more3.2.15, 4.1.8, 4.2.26
OSV records
GHSA-pgf9-h69p-pcgf

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2015-5211.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
spring-core@2.5.6
3.2.15

Open the chart page →

4,532
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2015-5211.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
spring-core@3.0.7
3.2.15

Open the chart page →

4,906
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2015-5211.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
spring-core@3.0.7.RELEASE
3.2.15

Open the chart page →

19,295
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2015-5211.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
spring-core@2.5.6.SEC03
3.2.15

Open the chart page →

10,682
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2015-5211.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
spring-core@4.1.1.RELEASE
4.1.8

Open the chart page →

55,726
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2015-5211.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
spring-core@4.2.1.RELEASE
4.2.2

Open the chart page →

6,907

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
craigwillis/c2metadata-bd:latestae317d7e4724
spring-core@4.1.1.RELEASE
4.1.8
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
spring-core@3.0.7.RELEASE
3.2.15
1
jenkinsci/jenkins:2.67a1f33f004659
spring-core@2.5.6.SEC03
3.2.15
1
pedrocesarti/jmeter-docker:3.314851f144f57
spring-core@2.5.6
3.2.15
1
xetusoss/archiva:v2.2.588f25242b9ee
spring-core@4.2.1.RELEASE
4.2.2
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
spring-core@3.0.7
3.2.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.