localstack
Chainguard
Status
Impact
This CVE is a transitive dependency brought in via amazon-kinesis-client-python, the fixed version of commons-beanutils does not currently exist in amazon-kclpy's most recent version (v3.0.3). The amazon-kclpy maintainers will need to implement a fix in a release.
Status