StackRadar

CVE-2023-34040

High

Advisory

Published 24 Aug 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

Spring-Kafka has Java Deserialization vulnerability When Improperly Configured

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
spring-kafkamaven2.8.4, 2.8.7, 2.8.11, 3.0.5+1 more2.9.11, 3.0.1021
OSV records
GHSA-crqf-q9fp-hwjw

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
spring-kafka@2.8.4
2.9.11

Open the chart page →

7,901
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
spring-kafka@3.0.7
3.0.10

Open the chart page →

2,326
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-kafka@3.0.7
3.0.10

Open the chart page →

2,205
airports-apiairports-api0.1.01 of 1See more

airports-api airports-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
spring-kafka@3.0.5
3.0.10

Open the chart page →

1,958
airports-consumerairports-consumer0.1.01 of 1See more

airports-consumer airports-consumer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
dina1993/airports-consumer:latest669d146a5e63
spring-kafka@3.0.5
3.0.10

Open the chart page →

1,947
airports-producerairports-producer0.1.01 of 1See more

airports-producer airports-producer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
dina1993/airports-producer:latest3d6b0dac1cb4
spring-kafka@3.0.5
3.0.10

Open the chart page →

1,947
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
spring-kafka@2.8.4
2.9.11

Open the chart page →

13,459
helm-airportshelm-airports0.1.03 of 7See more

helm-airports helm-airports 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
spring-kafka@3.0.5
3.0.10
dina1993/airports-consumer:latest669d146a5e63
spring-kafka@3.0.5
3.0.10
dina1993/airports-producer:latest3d6b0dac1cb4
spring-kafka@3.0.5
3.0.10

Open the chart page →

12,696
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-kafka@3.0.7
3.0.10

Open the chart page →

3,083
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-kafka@2.8.7
2.9.11

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
spring-kafka@2.8.7
2.9.11

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-kafka@2.8.7
2.9.11

Open the chart page →

5,873
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
spring-kafka@2.8.11
2.9.11

Open the chart page →

34,671
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-kafka@2.8.4
2.9.11

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
spring-kafka@2.8.4
2.9.11

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-kafka@2.8.4
2.9.11

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-kafka@2.8.4
2.9.11

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-kafka@2.8.4
2.9.11

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
spring-kafka@2.8.4
2.9.11

Open the chart page →

13,100
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2023-34040.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-kafka@2.8.11
2.9.11
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
spring-kafka@2.8.11
2.9.11
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
spring-kafka@2.8.11
2.9.11
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
spring-kafka@2.8.11
2.9.11

Open the chart page →

13,646

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dina1993/airports-api:latestac731244aed1
spring-kafka@3.0.5
3.0.10
2
dina1993/airports-consumer:latest669d146a5e63
spring-kafka@3.0.5
3.0.10
2
dina1993/airports-producer:latest3d6b0dac1cb4
spring-kafka@3.0.5
3.0.10
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
spring-kafka@2.8.4
2.9.11
2
andrianrf/backoffice-be:latest6036614803d4
spring-kafka@2.8.11
2.9.11
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-kafka@2.8.11
2.9.11
1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
spring-kafka@2.8.11
2.9.11
1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
spring-kafka@2.8.11
2.9.11
1
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
spring-kafka@2.8.11
2.9.11
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-kafka@2.8.4
2.9.11
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
spring-kafka@2.8.4
2.9.11
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-kafka@2.8.4
2.9.11
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-kafka@2.8.4
2.9.11
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-kafka@2.8.4
2.9.11
1
gurolakman/ussigw-core:1.0.48739565c3ea2
spring-kafka@2.8.4
2.9.11
1
vitalii1992/analytics-service:latest8e798836ecea
spring-kafka@3.0.7
3.0.10
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-kafka@3.0.7
3.0.10
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-kafka@2.8.7
2.9.11
1
vlebediantsev/registration-ms-final:latest427af418b75e
spring-kafka@2.8.7
2.9.11
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-kafka@2.8.7
2.9.11
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-kafka@3.0.7
3.0.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.