4.3
CVSS V3
Status
Impact
Commons-io v2.9.0 is a transitive dependency that is brought in under the resteasy-client-api, even the most up to date version of the 4.x.x version stream (4.7.9) contains the affected version of commons-io. This requires the upstream maintainers to implement a fix.
Status