StackRadar

CVE-2016-1000031

Critical

Advisory

Published 21 Dec 2018In the index since 8 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.337
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

Improper Access Control in commons-fileupload

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
commons-fileuploadmaven1.2.1, 1.3, 1.3.1, 1.3.1-jenkins-1+1 more1.3.318
OSV records
GHSA-7x9j-7223-rg5m

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
ignitecloudnativeapp1.0.01 of 1See more

ignite cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2016-1000031.

Container imageDigestPackageFixed in
apacheignite/ignite:2.7.0d7deab68b8fa
commons-fileupload@1.3.2
1.3.3

Open the chart page →

7,891
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2016-1000031.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
commons-fileupload@1.2.1
1.3.3

Open the chart page →

4,906
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2016-1000031.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
commons-fileupload@1.3.2
1.3.3

Open the chart page →

27,949
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2016-1000031.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
commons-fileupload@1.3.1-jenkins-1
1.3.3

Open the chart page →

10,682
polyglotncsaVerified publisher0.1.114 of 18See more

polyglot ncsa 0.1.1

14 of the 18 container images this version deploys carry CVE-2016-1000031.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
commons-fileupload@1.3.1
1.3.3
ncsapolyglot/converters-avconv:latestc44b22eb58bb
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-flac:latest072cf5bc6f99
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-gdal:latestf746049515c1
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-ghostscript:latestf350da56dd55
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-htmldoc:latest317dd9e56922
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-txt2html:latest30ee96508c0b
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
commons-fileupload@1.3
1.3.3
ncsapolyglot/converters-zip:latestf889fe30e2c7
commons-fileupload@1.3
1.3.3
ncsapolyglot/polyglot:2.4.097a8c01c076e
commons-fileupload@1.3
1.3.3

Open the chart page →

55,726

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apacheignite/ignite:2.7.0d7deab68b8fa
commons-fileupload@1.3.2
1.3.3
1
craigwillis/c2metadata-bd:latestae317d7e4724
commons-fileupload@1.3.1
1.3.3
1
jenkinsci/jenkins:2.67a1f33f004659
commons-fileupload@1.3.1-jenkins-1
1.3.3
1
ncsapolyglot/converters-avconv:latestc44b22eb58bb
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-flac:latest072cf5bc6f99
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-gdal:latestf746049515c1
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-ghostscript:latestf350da56dd55
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-htmldoc:latest317dd9e56922
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-txt2html:latest30ee96508c0b
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/converters-zip:latestf889fe30e2c7
commons-fileupload@1.3
1.3.3
1
ncsapolyglot/polyglot:2.4.097a8c01c076e
commons-fileupload@1.3
1.3.3
1
openkm/openkm-ce:6.3.113bc465a7461b
commons-fileupload@1.3.2
1.3.3
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
commons-fileupload@1.2.1
1.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.