wso2is
Chainguard
Status
Impact
jersey-client is pulled into wso2is as a transitive dependency through carbon.identity.server, carbon.identity.framework, carbon.registry, and apache.solr. In carbon.identity.framework, carbon.registry remains at v4.8.37[1] which which pulls in jersey-client v3.5.1. Upstream maintainers will need to increase the versions throughout the dependency chain for this vulnerability to be remediated. [1] https://github.com/wso2/carbon-identity-framework/blob/master/pom.xml#L2080
Status