StackRadar

CVE-2016-5007

High

Advisory

Published 17 Oct 2018In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
2 of 2
affected packages

Spring Security and Spring Framework may not recognize certain paths that should be protected

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
spring-coremaven2.5.6, 2.5.6.SEC03, 3.0.7, 3.0.7.RELEASE+3 more4.3.17
spring-security-coremaven3.0.4, 3.2.3, 3.2.10.RELEASE, 3.3.14.1.14
OSV records
GHSA-8crv-49fr-2h6j

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
spring-core@2.5.6
4.3.1

Open the chart page →

4,532
cosbenchcloudnativeapp1.0.11 of 1See more

cosbench cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
zenko/zenko-cosbench:0.0.6386a1f48ec0e
spring-core@3.0.7
4.3.1

Open the chart page →

4,906
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
spring-security-core@3.2.3
4.1.1

Open the chart page →

23,665
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
spring-security-core@3.3.1
4.1.1

Open the chart page →

19,802
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
spring-core@3.2.18.RELEASE
spring-security-core@3.2.10.RELEASE
4.3.1
4.1.1

Open the chart page →

27,949
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
spring-core@3.0.7.RELEASE
4.3.1

Open the chart page →

19,295
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
spring-core@2.5.6.SEC03
4.3.1

Open the chart page →

10,682
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
spring-core@4.1.1.RELEASE
4.3.1

Open the chart page →

55,726
archivaslamdev0.0.71 of 2See more

archiva slamdev 0.0.7

1 of the 2 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
xetusoss/archiva:v2.2.588f25242b9ee
spring-core@4.2.1.RELEASE
4.3.1

Open the chart page →

6,907
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2016-5007.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
4.1.1

Open the chart page →

8,554

Container images carrying it

10 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
craigwillis/c2metadata-bd:latestae317d7e4724
spring-core@4.1.1.RELEASE
4.3.1
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
spring-core@3.0.7.RELEASE
4.3.1
1
jenkinsci/jenkins:2.67a1f33f004659
spring-core@2.5.6.SEC03
4.3.1
1
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
4.1.1
1
openkm/openkm-ce:6.3.113bc465a7461b
spring-core@3.2.18.RELEASE
spring-security-core@3.2.10.RELEASE
4.3.1
4.1.1
1
pedrocesarti/jmeter-docker:3.314851f144f57
spring-core@2.5.6
4.3.1
1
rundeck/rundeck:3.2.74d64fe56f767
spring-security-core@3.3.1
4.1.1
1
rundeck/rundeck:3.0.16b13e8059ad72
spring-security-core@3.2.3
4.1.1
1
xetusoss/archiva:v2.2.588f25242b9ee
spring-core@4.2.1.RELEASE
4.3.1
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
spring-core@3.0.7
4.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.