CVE-2024-22243
HighAdvisory
Published 23 Feb 2024In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.1
- base score, highest
- EPSS
- 0.040
- 90th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 289
- of 17,781 indexed, latest versions
- Container images
- 243
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
Carried by container images the latest versions of 289 of 17,781 indexed charts deploy, on 243 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| spring-webmaven | 2.5.6.SEC03, 3.2.18.RELEASE, 4.1.1.RELEASE, 4.2.1.RELEASE+71 more | 5.3.32, 6.0.17, 6.1.4 | 243 |
- OSV records
- GHSA-ccgv-vj62-xf9h
Charts affected
289 by stars
Container images carrying it
243 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apache/ | c8fb51195444 | spring-web | 5.3.32 | 1 |
| apacherocketmq/ | 24799aff6cf8 | spring-web | no fix listed | 1 |
| apache/ | e2be712fc4f4 | spring-web | 5.3.32 | 1 |
| apache/ | 1bd5756f6273 | spring-web | 5.3.32 | 1 |
| apache/ | 295f1dc87d98 | spring-web | 5.3.32 | 1 |
| apache/ | 67d50e4deff4 | spring-web | no fix listed | 1 |
| apache/ | 80530f0308a5 | spring-web | 5.3.32 | 1 |
| apimap/ | ae2b3ab00177 | spring-web | 5.3.32 | 1 |
| aroralalit/ | 2a094f597b36 | spring-web | 5.3.32 | 1 |
| arturisimo/ | fff9de644941 | spring-web | 5.3.32 | 1 |
| arturisimo/ | c95524e90b57 | spring-web | 5.3.32 | 1 |
| assistiot/ | e4414cb72dc4 | spring-web | 5.3.32 | 1 |
| atlassian/ | 3b9222ab32ef | spring-web | no fix listed | 1 |
| atlassian/ | ebf761c7d437 | spring-web | 5.3.32 | 1 |
| atlassian/ | 37bc46cbec1a | spring-web | no fix listed | 1 |
| atlassian/ | 64a75aa4ec4e | spring-web | 5.3.32 | 1 |
| audig/ | 2c3fe34ee430 | spring-web | no fix listed | 1 |
| beastob/ | 99a49885ab33 | spring-web | 5.3.32 | 1 |
| binhex/ | fb8952921ab6 | spring-web | no fix listed | 1 |
| chandanteekinavar/ | 0cf52bf5ee9a | spring-web | 5.3.32 | 1 |
| choerodon/ | 3c94c97f6f69 | spring-web | no fix listed | 1 |
| cnieg/ | d4b478d76f2a | spring-web | 5.3.32 | 1 |
| commerceexperts/ | 9e33ad89baf6 | spring-web | 5.3.32 | 1 |
| craigwillis/ | ae317d7e4724 | spring-web | no fix listed | 1 |
| dannielkil/ | e3b479a55a69 | spring-web | 5.3.32 | 1 |
| davidvmar/ | 0d221e834a21 | spring-web | no fix listed | 1 |
| dellcloud/ | 02fc234353a9 | spring-web | no fix listed | 1 |
| dellcloud/ | 4d2eb25b9225 | spring-web | 5.3.32 | 1 |
| dniel/ | f67129ea1c64 | spring-web | no fix listed | 1 |
| drpcorg/ | 8858fae1859d | spring-web | 5.3.32 | 1 |
| egdsandaru/ | 681baa1926f4 | spring-web | no fix listed | 1 |
| elastictranscoder/ | 963ab3858c6b | spring-web | 5.3.32 | 1 |
| elastictranscoder/ | 26208b8c2359 | spring-web | 5.3.32 | 1 |
| elastictranscoder/ | b4a0327029e6 | spring-web | 5.3.32 | 1 |
| elastictranscoder/ | 5b75d19e2733 | spring-web | 5.3.32 | 1 |
| emeraldpay/ | 126f0ae0b388 | spring-web | 5.3.32 | 1 |
| emeraldpay/ | ac2a4bc66ab6 | spring-web | 5.3.32 | 1 |
| expediagroup/ | 4f2cf61e7de9 | spring-web | 5.3.32 | 1 |
| farberg/ | 4b4a22487394 | spring-web | 5.3.32 | 1 |
| fimperato/ | 6441f6545613 | spring-web | 5.3.32 | 1 |
| fimperato/ | e32920eedd3a | spring-web | 5.3.32 | 1 |
| fimperato/ | 604012b77841 | spring-web | no fix listed | 1 |
| fimperato/ | c0cfaca070d9 | spring-web | 5.3.32 | 1 |
| fjvela/ | 70cebf67bd66 | spring-web | no fix listed | 1 |
| flofree/ | 6b6486c5f81e | spring-web | 5.3.32 | 1 |
| franrobles8/ | 99985392d63c | spring-web | 5.3.32 | 1 |
| gdrocha/ | d5ae64e83d4c | spring-web | 6.0.17 | 1 |
| geonetwork/ | 20c9bb761f67 | spring-web | no fix listed | 1 |
| geoservercloud/ | ca58b74529cd | spring-web | no fix listed | 1 |
| geoservercloud/ | 5dc0c93a1710 | spring-web | no fix listed | 1 |