CVE-2018-1275
CriticalAdvisory
Published 17 Oct 2018In the index since 8 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.576
- 99th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Spring Framework has Improperly Implemented Security Check for Standard
Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| spring-messagingmaven | 4.3.1.RELEASE, 4.3.2.RELEASE, 4.3.6.RELEASE, 4.3.7.RELEASE+1 more | 4.3.16.RELEASE | 6 |
- OSV records
- GHSA-3rmv-2pg5-xvqj
Charts affected
4 by stars
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| choerodon/ | 3c94c97f6f69 | spring-messaging | 4.3.16.RELEASE | 1 |
| just1not2/ | 8a2305192dec | spring-messaging | 4.3.16.RELEASE | 1 |
| polyakov/ | dbcef69146b8 | spring-messaging | 4.3.16.RELEASE | 1 |
| richardchesterwood/ | 518f946b9f05 | spring-messaging | 4.3.16.RELEASE | 1 |
| richardchesterwood/ | 0b540a28f5a6 | spring-messaging | 4.3.16.RELEASE | 1 |
| richardchesterwood/ | 36c43961214c | spring-messaging | 4.3.16.RELEASE | 1 |