/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-mp3x-m375-hgcr

Published

Last updated

https://images.chainguard.dev/security/CGA-mp3x-m375-hgcr
Package

wso2is

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-5115
  • GHSA-mmxm-8w33-wc4h

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-5115

Updates

Status

Pending upstream fix

Impact

The vulnerability originates from a component used within the package, Solr 9.5.0, which bundles Jetty 10.0.20. The upstream project needs to upgrade the package and use a Solr version that upgrades Jetty to 10.0.26, the patched release. Once that’s available, we can upgrade and remediate the CVE.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing