/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-m8jp-vqj4-r47j

Published

Last updated

https://images.chainguard.dev/security/CGA-m8jp-vqj4-r47j
Package

wso2is

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-6763
  • GHSA-qh8g-58pp-2wxh

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-6763

Updates

Status

Pending upstream fix

Impact

This vulnerability originates from 'jetty-http', which is a transitive dependency multiple levels deep in the dependency tree. The wso2is project depends on carbon.registry, which in turn depends on 'solr', which contains the affected jetty-http version. Attempts at upgrading the top-level dependency were not successful, the latest version of carbon.registry pins to the affected version of solr. Pending fix from upstream.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing