StackRadar

CVE-2024-38827

Medium

Advisory

Published 2 Dec 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
112
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

Carried by container images the latest versions of 112 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven3.0.4, 3.2.10.RELEASE, 4.1.3.RELEASE, 4.2.2.RELEASE+51 more5.7.14, 5.8.16, 6.0.14, 6.1.12+2 more130
OSV records
GHSA-q3v6-hm2v-pw99

Charts affected

112 by stars
ChartLatestAffected imagesRadar Score
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-core@5.1.5.RELEASE
5.7.14

Open the chart page →

6,101
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-core@5.7.5
5.7.14

Open the chart page →

13,646
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
5.7.14

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.2.1-plain
5.7.14

Open the chart page →

18,756
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-core@5.2.1.RELEASE
5.7.14

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-core@5.7.1
5.7.14

Open the chart page →

25,394
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-security-core@6.1.5
6.1.12

Open the chart page →

3,221
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.7.14

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.7.14

Open the chart page →

28,605
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-security-core@6.3.3
6.3.5

Open the chart page →

2,634
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-security-core@6.2.0
6.2.8

Open the chart page →

11,577
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-security-core@5.7.6
5.7.14

Open the chart page →

5,846

Container images carrying it

130 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-security-core@5.4.1
5.7.14
1
flowable/flowable-rest:7.1.0b7ae287502cd
spring-security-core@6.3.3
6.3.5
1
folioci/mod-agreements:latest29c3f233a498
spring-security-core@6.1.2
6.1.12
1
folioci/mod-licenses:latestcfd6109bf477
spring-security-core@6.1.2
6.1.12
1
folioci/mod-oa:latestae3b069d4ba5
spring-security-core@6.1.2
6.1.12
1
folioci/mod-serials-management:latest571fa1ffe8c9
spring-security-core@6.1.2
6.1.12
1
folioci/mod-service-interaction:latestf53c327a48e8
spring-security-core@6.1.2
6.1.12
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-security-core@6.1.5
6.1.12
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
spring-security-core@5.3.6.RELEASE
5.7.14
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-security-core@5.3.4.RELEASE
5.7.14
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-security-core@5.3.4.RELEASE
5.7.14
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-security-core@5.3.4.RELEASE
5.7.14
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-security-core@5.3.4.RELEASE
5.7.14
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-security-core@5.3.4.RELEASE
5.7.14
1
gocd/gocd-server:v19.3.02da45cb09d57
spring-security-core@4.2.11.RELEASE
5.7.14
1
gocd/gocd-server:v26.1.0720d1012b93f
spring-security-core@4.2.20.RELEASE
5.7.14
1
gotson/komga:0.99.49b15ea6bfc30
spring-security-core@5.5.0
5.7.14
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
spring-security-core@5.7.4
5.7.14
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
spring-security-core@5.7.4
5.7.14
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-security-core@5.6.2
5.7.14
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
spring-security-core@5.6.2
5.7.14
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
spring-security-core@5.6.2
5.7.14
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-security-core@5.6.2
5.7.14
1
hazelcast/management-center:5.3.2f9d34300d330
spring-security-core@5.7.10
5.7.14
1
housewrecker/gaps:latestf417dd0a7547
spring-security-core@5.6.2
5.7.14
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
spring-security-core@6.2.2
6.2.8
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
spring-security-core@5.8.14
5.8.16
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
spring-security-core@5.8.11
5.8.16
1
jhipster/jhipster-registry:latest7184525acd4d
spring-security-core@5.7.3
5.7.14
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
spring-security-core@5.7.11
5.7.14
1
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
5.7.14
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
spring-security-core@5.4.1
5.7.14
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-security-core@5.3.4.RELEASE
5.7.14
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-security-core@5.3.4.RELEASE
5.7.14
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-security-core@5.4.5
5.7.14
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-security-core@6.3.3
6.3.5
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-security-core@6.1.4
6.1.12
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-security-core@6.1.4
6.1.12
1
nacos/nacos-server:1.4.1fe6e5688cdf3
spring-security-core@5.1.12.RELEASE
5.7.14
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
spring-security-core@5.8.14
5.8.16
1
openkm/openkm-ce:6.3.113bc465a7461b
spring-security-core@3.2.10.RELEASE
5.7.14
1
platform9community/api-gateway:latest40a4970de568
spring-security-core@5.3.3.RELEASE
5.7.14
1
platform9community/customers-service:latest2089811e5cc6
spring-security-core@5.3.3.RELEASE
5.7.14
1
platform9community/vets-service:latestd1165c94dfb3
spring-security-core@5.3.3.RELEASE
5.7.14
1
platform9community/visits-service:latest8d11b50368c6
spring-security-core@5.3.3.RELEASE
5.7.14
1
remche/shinyproxy:2.6.18bcda8a04d3b
spring-security-core@5.5.5
5.7.14
1
reportportal/service-api:5.7.29df41f8fb320
spring-security-core@5.2.4.RELEASE
5.7.14
1
reportportal/service-authorization:5.7.09e73114dbd15
spring-security-core@5.2.4.RELEASE
5.7.14
1
rundeck/rundeck:3.2.74d64fe56f767
spring-security-core@4.2.13.RELEASE
5.7.14
1
rundeck/rundeck:3.0.16b13e8059ad72
spring-security-core@4.2.7.RELEASE
5.7.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.