StackRadar

CVE-2023-34053

High

Advisory

Published 28 Nov 2023In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework vulnerable to denial of service

Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
spring-webmvcmaven6.0.7, 6.0.9, 6.0.10, 6.0.11+2 more6.0.1418
OSV records
GHSA-v94h-hvhg-mf9h

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
spring-webmvc@6.0.9
6.0.14

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
spring-webmvc@6.0.9
6.0.14

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-webmvc@6.0.9
6.0.14

Open the chart page →

2,853
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
spring-webmvc@6.0.9
6.0.14

Open the chart page →

2,221
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-webmvc@6.0.9
6.0.14

Open the chart page →

2,205
airports-apiairports-api0.1.01 of 1See more

airports-api airports-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
spring-webmvc@6.0.7
6.0.14

Open the chart page →

1,958
airports-consumerairports-consumer0.1.01 of 1See more

airports-consumer airports-consumer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
dina1993/airports-consumer:latest669d146a5e63
spring-webmvc@6.0.7
6.0.14

Open the chart page →

1,947
airports-producerairports-producer0.1.01 of 1See more

airports-producer airports-producer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
dina1993/airports-producer:latest3d6b0dac1cb4
spring-webmvc@6.0.7
6.0.14

Open the chart page →

1,947
helm-airportshelm-airports0.1.03 of 7See more

helm-airports helm-airports 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
spring-webmvc@6.0.7
6.0.14
dina1993/airports-consumer:latest669d146a5e63
spring-webmvc@6.0.7
6.0.14
dina1993/airports-producer:latest3d6b0dac1cb4
spring-webmvc@6.0.7
6.0.14

Open the chart page →

12,696
sys-info-web-env-view-serverhuajuan-helm-charts0.1.11 of 2See more

sys-info-web-env-view-server huajuan-helm-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
spring-webmvc@6.0.11
6.0.14

Open the chart page →

1,989
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
spring-webmvc@6.0.11
6.0.14

Open the chart page →

6,490
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
spring-webmvc@6.0.13
6.0.14

Open the chart page →

2,234
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-webmvc@6.0.7
6.0.14

Open the chart page →

3,290
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-webmvc@6.0.12
6.0.14

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-webmvc@6.0.12
6.0.14

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
spring-webmvc@6.0.12
6.0.14

Open the chart page →

4,599
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-webmvc@6.0.9
6.0.14

Open the chart page →

3,083
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-webmvc@6.0.13
6.0.14

Open the chart page →

3,221
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-34053.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
spring-webmvc@6.0.10
6.0.14

Open the chart page →

3,480

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dina1993/airports-api:latestac731244aed1
spring-webmvc@6.0.7
6.0.14
2
dina1993/airports-consumer:latest669d146a5e63
spring-webmvc@6.0.7
6.0.14
2
dina1993/airports-producer:latest3d6b0dac1cb4
spring-webmvc@6.0.7
6.0.14
2
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-webmvc@6.0.13
6.0.14
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
spring-webmvc@6.0.11
6.0.14
1
kubebb/mesh-api:v5.7.0a3879931dfa1
spring-webmvc@6.0.11
6.0.14
1
lavandadelpatio/tmdb:latestded9377636e9
spring-webmvc@6.0.13
6.0.14
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-webmvc@6.0.7
6.0.14
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-webmvc@6.0.12
6.0.14
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-webmvc@6.0.12
6.0.14
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
spring-webmvc@6.0.12
6.0.14
1
vitalii1992/account-service:latest0e694d94551d
spring-webmvc@6.0.9
6.0.14
1
vitalii1992/analytics-service:latest8e798836ecea
spring-webmvc@6.0.9
6.0.14
1
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-webmvc@6.0.9
6.0.14
1
vitalii1992/order-service:latest07c4a8833ce4
spring-webmvc@6.0.9
6.0.14
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-webmvc@6.0.9
6.0.14
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
spring-webmvc@6.0.10
6.0.14
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-webmvc@6.0.9
6.0.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.