Package
wso2is
Component
cxf-core
Latest update
Fixed version
7.3.0-r0
5.6
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
7.3.0-r0Status
Impact
The vulnerability in cxf-core (< 3.5.11) originates from a transitive dependency introduced via carbon-deployment (https://github.com/wso2/carbon-deployment). Although a fix is available in version 3.5.11 and above, enforcing this upgrade at the product root level was unsuccessful. Upstream must update the dependency to resolve the issue, after which we can proceed with remediation. [v2-migration]
Status