StackRadar

CVE-2016-6814

Critical

Advisory

Published 13 May 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.172
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
2 of 2
affected packages

Deserialization of Untrusted Data in Groovy

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
groovy-allmaven2.2.2, 2.4.42.4.89
groovymaven2.4.6-indy, 2.4.72.4.82
OSV records
GHSA-xphj-m9cc-8fmq

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.8
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
groovy-all@2.4.4
2.4.8

Open the chart page →

20,837
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
groovy-all@2.4.4
2.4.8

Open the chart page →

8,198
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.8

Open the chart page →

6,882
stormgresearch1.2.01 of 3See more

storm gresearch 1.2.0

1 of the 3 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
library/storm:2.4.0bd5d420506d6
groovy-all@2.4.4
2.4.8

Open the chart page →

6,165
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.8
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
groovy-all@2.4.4
2.4.8

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.8

Open the chart page →

6,882
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
library/elasticsearch:2.4.641ed3a1a16b6
groovy@2.4.6-indy
2.4.8

Open the chart page →

4,911
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
groovy-all@2.2.2
2.4.8

Open the chart page →

13,607
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
groovy-all@2.2.2
2.4.8

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
groovy-all@2.2.2
2.4.8

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
groovy-all@2.2.2
2.4.8

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
groovy-all@2.2.2
2.4.8

Open the chart page →

13,100
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2016-6814.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
groovy@2.4.7
2.4.8

Open the chart page →

8,554

Container images carrying it

11 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
groovy-all@2.4.4
2.4.8
4
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
groovy-all@2.4.4
2.4.8
2
gurolakman/smsf-configuration:1.0.49abb3882bcbd
groovy-all@2.2.2
2.4.8
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
groovy-all@2.2.2
2.4.8
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
groovy-all@2.2.2
2.4.8
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
groovy-all@2.2.2
2.4.8
1
gurolakman/ussigw-core:1.0.48739565c3ea2
groovy-all@2.2.2
2.4.8
1
just1not2/streama:1.10.48a2305192dec
groovy@2.4.7
2.4.8
1
library/elasticsearch:2.4.641ed3a1a16b6
groovy@2.4.6-indy
2.4.8
1
library/storm:2.4.0bd5d420506d6
groovy-all@2.4.4
2.4.8
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
groovy-all@2.4.4
2.4.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.