StackRadar

CVE-2024-38827

Medium

Advisory

Published 2 Dec 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
112
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

Carried by container images the latest versions of 112 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
spring-security-coremaven3.0.4, 3.2.10.RELEASE, 4.1.3.RELEASE, 4.2.2.RELEASE+51 more5.7.14, 5.8.16, 6.0.14, 6.1.12+2 more130
OSV records
GHSA-q3v6-hm2v-pw99

Charts affected

112 by stars
ChartLatestAffected imagesRadar Score
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-security-core@5.1.5.RELEASE
5.7.14

Open the chart page →

6,101
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-core@5.7.5
5.7.14

Open the chart page →

13,646
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
spring-security-core@3.0.4
5.7.14

Open the chart page →

8,554
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
spring-security-core@5.2.1-plain
5.7.14

Open the chart page →

18,756
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-core@5.2.1.RELEASE
5.7.14

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
spring-security-core@5.7.1
5.7.14

Open the chart page →

25,394
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-security-core@6.1.5
6.1.12

Open the chart page →

3,221
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.7.14

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.7.14

Open the chart page →

28,605
hazelcastwenerme5.10.21 of 2See more

hazelcast wenerme 5.10.2

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
hazelcast/management-center:5.5.2991ddb27c251
spring-security-core@6.3.3
6.3.5

Open the chart page →

2,634
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-security-core@6.2.0
6.2.8

Open the chart page →

11,577
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-38827.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-security-core@5.7.6
5.7.14

Open the chart page →

5,846

Container images carrying it

130 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
spring-security-core@5.2.1.RELEASE
5.7.14
3
provectuslabs/kafka-ui:latest8f2ff02d64b0
spring-security-core@6.1.3
6.1.12
3
apache/nifi-registry:1.26.07cdfd8deec92
spring-security-core@5.8.11
5.8.16
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
spring-security-core@5.3.4.RELEASE
5.7.14
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
spring-security-core@5.3.4.RELEASE
5.7.14
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
spring-security-core@5.3.4.RELEASE
5.7.14
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
spring-security-core@5.3.4.RELEASE
5.7.14
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
spring-security-core@5.3.4.RELEASE
5.7.14
2
hazelcast/management-center:5.5.2991ddb27c251
spring-security-core@6.3.3
6.3.5
2
hookiesolutions/webhookie:latest0629694246ba
spring-security-core@5.6.1
5.7.14
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
spring-security-core@5.8.7
5.8.16
2
nacos/nacos-server:v2.1.0dcf04549c6d7
spring-security-core@5.1.12.RELEASE
5.7.14
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
spring-security-core@5.6.0
5.7.14
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
spring-security-core@5.6.0
5.7.14
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
spring-security-core@5.5.0
5.7.14
1
andrianrf/backoffice-be:latest6036614803d4
spring-security-core@5.7.8
5.7.14
1
andrianrf/bpjstk-service:latest46abe878d9d8
spring-security-core@5.3.4.RELEASE
5.7.14
1
andrianrf/iso-client:latestba560086ce15
spring-security-core@5.3.4.RELEASE
5.7.14
1
apache/nifi-registry:1.14.0090b7f87ec7f
spring-security-core@5.5.0
5.7.14
1
apache/nifi-registry:1.27.063b8e3e40742
spring-security-core@5.8.13
5.8.16
1
apache/nifi-registry:0.8.0974efa2f21da
spring-security-core@5.2.2.RELEASE
5.7.14
1
apache/ranger:2.7.076c176e8a0e4
spring-security-core@5.7.12
5.7.14
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
spring-security-core@5.6.5
5.7.14
1
apimap/api:v1.8.11ae2b3ab00177
spring-security-core@5.7.4
5.7.14
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
spring-security-core@5.7.1
5.7.14
1
atlassian/confluence-server:7.10.03b9222ab32ef
spring-security-core@4.2.16.RELEASE
5.7.14
1
atlassian/crowd:5.2.2ebf761c7d437
spring-security-core@5.5.8
5.7.14
1
atlassian/jira-software:8.14.037bc46cbec1a
spring-security-core@5.2.1.RELEASE
5.7.14
1
atlassian/jira-software:9.7.264a75aa4ec4e
spring-security-core@5.4.5
5.7.14
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
spring-security-core@5.3.3.RELEASE
5.7.14
1
choerodon/event-store-service:0.8.03c94c97f6f69
spring-security-core@4.2.2.RELEASE
5.7.14
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
spring-security-core@5.7.10
5.7.14
1
craigwillis/c2metadata-bd:latestae317d7e4724
spring-security-core@4.1.3.RELEASE
5.7.14
1
dannielkil/book-backend:lateste3b479a55a69
spring-security-core@5.7.3
5.7.14
1
drpcorg/dshackle:0.54.08858fae1859d
spring-security-core@5.5.3
5.7.14
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
spring-security-core@6.2.2
6.2.8
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
spring-security-core@4.2.17.RELEASE
5.7.14
1
elastictranscoder/media:627e21dc963ab3858c6b
spring-security-core@5.5.0
5.7.14
1
elastictranscoder/media-storage:f6d861a026208b8c2359
spring-security-core@5.5.0
5.7.14
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
spring-security-core@5.5.0
5.7.14
1
emeraldpay/dshackle:0.14.0126f0ae0b388
spring-security-core@5.5.3
5.7.14
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
spring-security-core@5.5.3
5.7.14
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
spring-security-core@5.7.5
5.7.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.