/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-f5rx-9c8f-74fx

Published

Last updated

https://images.chainguard.dev/security/CGA-f5rx-9c8f-74fx
Package

cassandra-reaper

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2020-8908
  • GHSA-5mg8-w23w-74h3

Severity

3.3

Low

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2020-8908

Updates

Status

Pending upstream fix

Impact

Pending upstream fix, this fix will require some code changes since when we upgrade the "com.google.guava:guava" dependency version from 24.1.1 which is the version project is currently using to 32.0.0 which is the version we should bump to to fix the CVEs but we can't because the build was failed due to compilation errors.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing