/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-jwxg-cjjq-4858

Published

Last updated

https://images.chainguard.dev/security/CGA-jwxg-cjjq-4858
Package

cassandra-reaper-jre-bcfips

Repository

Chainguard

Latest Update
Fixed
Fixed Version

3.7.1-r1

Aliases
  • CVE-2023-2976
  • GHSA-7g45-4rm6-3mm3

Severity

7.1

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-2976

Updates

Status

Fixed

Fixed version

3.7.1-r1

Status

Pending upstream fix

Impact

Pending upstream fix, this fix will require some code changes since when we upgrade the "com.google.guava:guava" dependency version from 24.1.1 which is the version project is currently using to 32.0.0 which is the version we should upgrade to fix the CVEs but we can't because the build was failed due to compilation errors.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing