CVE-2024-38827
MediumAdvisory
Published 2 Dec 2024In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.8
- base score, highest
- EPSS
- 0.004
- 31st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 112
- of 17,781 indexed, latest versions
- Container images
- 130
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
Carried by container images the latest versions of 112 of 17,781 indexed charts deploy, on 130 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| spring-security-coremaven | 3.0.4, 3.2.10.RELEASE, 4.1.3.RELEASE, 4.2.2.RELEASE+51 more | 5.7.14, 5.8.16, 6.0.14, 6.1.12+2 more | 130 |
- OSV records
- GHSA-q3v6-hm2v-pw99
Charts affected
112 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| umsappstacksimplifyVerified publisher | 1.0.0 | 1 of 3See more | 6,101 |
| static-src-people-detector-appstatic-src-people-detector-chartVerified publisher | 1.5.5 | 1 of 6See more | 13,646 |
| streamastreama | 1.0.1 | 1 of 2See more | 8,554 |
| rundecksvtech-public-helm-charts | 1.0.0 | 1 of 2See more | 18,756 |
| shenyutest-helm | 2.4.21 | 1 of 2See more | 12,513 |
| thingsboardthingsboardVerified publisher | 0.1.3 | 1 of 12See more | 25,394 |
| togglr-backendtogglrVerified publisher | 1.0.0 | 1 of 1See more | 3,221 |
| webhookiewebhookie | 0.1.2 | 1 of 1See more | 14,364 |
| webhookie-allwebhookie | 0.1.2 | 1 of 3See more | 28,605 |
| hazelcastwenerme | 5.10.2 | 1 of 2See more | 2,634 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,577 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 1 of 2See more | 5,846 |
Container images carrying it
130 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| scorpiobroker/ | db55012043df | spring-security-core | 5.7.14 | 1 |
| seataio/ | 703b5de7f1a6 | spring-security-core | 5.7.14 | 1 |
| seataio/ | ee1ed55f4144 | spring-security-core | 5.7.14 | 1 |
| seldonio/ | ba81b17f00eb | spring-security-core | 5.7.14 | 1 |
| seldonio/ | eea0d3f578ca | spring-security-core | 5.7.14 | 1 |
| svtechnmaa/ | 6e368ace0977 | spring-security-core | 5.7.14 | 1 |
| thingsboard/ | 645f43b688f7 | spring-security-core | 5.7.14 | 1 |
| thingsboard/ | f40a542832c4 | spring-security-core | 5.7.14 | 1 |
| thmmniii/ | 5438517d9fc2 | spring-security-core | 5.7.14 | 1 |
| vitalii1992/ | 0e694d94551d | spring-security-core | 6.1.12 | 1 |
| vitalii1992/ | 8e798836ecea | spring-security-core | 6.1.12 | 1 |
| vitalii1992/ | aabe6ac39356 | spring-security-core | 6.1.12 | 1 |
| vitalii1992/ | 07c4a8833ce4 | spring-security-core | 6.1.12 | 1 |
| vlebediantsev/ | 10393a89b4a8 | spring-security-core | 5.7.14 | 1 |
| vlebediantsev/ | df8bf38c535b | spring-security-core | 5.7.14 | 1 |
| vlebediantsev/ | 427af418b75e | spring-security-core | 5.7.14 | 1 |
| vlebediantsev/ | 9319437f3c8f | spring-security-core | 5.7.14 | 1 |
| vrijbrp/ | 5c770c2ae48c | spring-security-core | 5.7.14 | 1 |
| zahoriaut/ | b2de13916f3e | spring-security-core | 5.7.14 | 1 |
| zbalogh/ | 7c247e399a1f | spring-security-core | 5.7.14 | 1 |
| gcr.io/ | 0ee5f968d2ab | spring-security-core | 5.7.14 | 1 |
| ghcr.io/ | ef3670f7e0a8 | spring-security-core | 5.7.14 | 1 |
| ghcr.io/ | baa4fa9549dc | spring-security-core | 5.7.14 | 1 |
| ghcr.io/ | c1b37e821f72 | spring-security-core | 5.7.14 | 1 |
| ghcr.io/ | 41b45003c6b6 | spring-security-core | 5.7.14 | 1 |
| ghcr.io/ | 8368359c8dd0 | spring-security-core | 5.7.14 | 1 |
| public.ecr.aws/ | 8cdcb7e83f9f | spring-security-core | 5.7.14 | 1 |
| quay.io/ | e383ba3e0966 | spring-security-core | 6.2.8 | 1 |
| quay.io/ | 2b3554029737 | spring-security-core | 6.0.14 | 1 |
| quay.io/ | 8ed603ab7417 | spring-security-core | 6.2.8 | 1 |