Package
apache-activemq-fips-6.1
Component
jetty-http
Latest update
3.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The jetty-http dependency at version 11.0.26 contains a vulnerability (GHSA-qh8g-58pp-2wxh) that is fixed in Jetty 12.0.12. This is a transitive dependency brought in via upstream Apache ActiveMQ and is part of a coherent set of jetty-* artifacts that cannot be bumped independently. Resolution requires:
Status