7.1
CVSS V3
Status
Justification
Impact
Scanner is correctly detecting guava v32.0.0 is installed, but is incorrectly reporting that it is vulnerable to this CVE. v32.0.0 contains the fix. See https://github.com/google/guava/releases/tag/v32.0.0 and https://github.com/keycloak/keycloak/pull/21544