/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-6q6g-33f5-98p5

Published

Last updated

https://images.chainguard.dev/security/CGA-6q6g-33f5-98p5
Package

apache-tika-3.0

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-6763
  • GHSA-qh8g-58pp-2wxh

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-6763

Updates

Status

Pending upstream fix

Impact

The upstream project has to fix the issue since if we try to bump the jetty-http version from 11.0.24 to the fixed version 12.0.12 the project did not compile

Status

Pending upstream fix

Impact

Attempting to patch this CVE leads to JAR dependency mismatch, and will require an update from upstream maintainers to remediate.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing