StackRadar

CVE-2024-22234

High

Advisory

Published 20 Feb 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven6.1.0, 6.1.2, 6.1.3, 6.1.4+2 more6.1.7, 6.2.214
OSV records
GHSA-w3w6-26f2-p474

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-security-core@6.1.3
6.1.7

Open the chart page →

15,562
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
spring-security-core@6.1.0
6.1.7

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
spring-security-core@6.1.0
6.1.7

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-security-core@6.1.0
6.1.7

Open the chart page →

2,853
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
spring-security-core@6.1.0
6.1.7

Open the chart page →

2,221
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-security-core@6.1.3
6.1.7

Open the chart page →

14,728
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
spring-security-core@6.1.2
6.1.7

Open the chart page →

1,874
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
spring-security-core@6.1.2
6.1.7

Open the chart page →

1,760
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
spring-security-core@6.1.2
6.1.7

Open the chart page →

1,733
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-core@6.1.2
6.1.7

Open the chart page →

1,733
mod-service-interactionfolio-org0.1.61 of 1See more

mod-service-interaction folio-org 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-core@6.1.2
6.1.7

Open the chart page →

1,733
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-security-core@6.1.4
6.1.7

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-security-core@6.1.4
6.1.7

Open the chart page →

5,129
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-security-core@6.1.3
6.1.7

Open the chart page →

1,597
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-security-core@6.1.5
6.1.7

Open the chart page →

3,221
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-22234.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-security-core@6.2.0
6.2.2

Open the chart page →

11,577

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-security-core@6.1.3
6.1.7
3
folioci/mod-agreements:latest29c3f233a498
spring-security-core@6.1.2
6.1.7
1
folioci/mod-licenses:latestcfd6109bf477
spring-security-core@6.1.2
6.1.7
1
folioci/mod-oa:latestae3b069d4ba5
spring-security-core@6.1.2
6.1.7
1
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-core@6.1.2
6.1.7
1
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-core@6.1.2
6.1.7
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-security-core@6.1.5
6.1.7
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-security-core@6.1.4
6.1.7
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-security-core@6.1.4
6.1.7
1
vitalii1992/account-service:latest0e694d94551d
spring-security-core@6.1.0
6.1.7
1
vitalii1992/analytics-service:latest8e798836ecea
spring-security-core@6.1.0
6.1.7
1
vitalii1992/api-gateway-service:latestaabe6ac39356
spring-security-core@6.1.0
6.1.7
1
vitalii1992/order-service:latest07c4a8833ce4
spring-security-core@6.1.0
6.1.7
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-security-core@6.2.0
6.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.