py3-hashin
Chainguard
8.8
CVSS CVSS_V3
Status
Justification
Impact
GHSA-5rjg-fvgr-3xxf is detected because pip vendors setuptools (v70.3.0), but only includes pkg_resources, making it non-vulnerable. More information can be found here: https://github.com/pypa/pip/tree/30807c4d9e62e0ba65ad80d441dba55e76ddf5e4/src/pip/_vendor#modifications We've upgraded setuptools to 78.1.1 in py3-cassandra-medusa to remediate the CVE.
Status