/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-7chh-rjg4-v8wp

Published

Last updated

https://images.chainguard.dev/security/CGA-7chh-rjg4-v8wp
Package

jenkins

RepositoryWolfi
Latest Update
Fix not planned
Aliases
  • CVE-2023-5072
  • GHSA-4jq9-2xhw-jpx7
  • GHSA-rm7j-f5g5-27vv

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-5072

Updates

Status

Fix not planned

Impact

Upstream is using a deprecated dependency (com.fasterxml.jackson.datatype:jackson-datatype-json-org). The CVE is matched to a dependency of this deprecated dependency (org.json:json). Upstream needs to migrate their code off this deprecated dependency.


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing