/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-f2fv-cm8p-mv53

Published

Last updated

https://images.chainguard.dev/security/CGA-f2fv-cm8p-mv53
Package

wso2is

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-12383
  • GHSA-7p63-w6x9-6gr7

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-12383

Updates

Status

Pending upstream fix

Impact

jersey-client is pulled into wso2is as a transitive dependency through carbon.identity.server, carbon.identity.framework, carbon.registry, and apache.solr. In carbon.identity.framework, carbon.registry remains at v4.8.37[1] which which pulls in jersey-client v3.5.1. Upstream maintainers will need to increase the versions throughout the dependency chain for this vulnerability to be remediated. [1] https://github.com/wso2/carbon-identity-framework/blob/master/pom.xml#L2080

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing