wso2is
Chainguard
5.6
CVSS V3
Status
Impact
The vulnerability in cxf-core (< 3.5.11) originates from a transitive dependency introduced via carbon-deployment (https://github.com/wso2/carbon-deployment). Although a fix is available in version 3.5.11 and above, enforcing this upgrade at the product root level was unsuccessful. Upstream must update the dependency to resolve the issue, after which we can proceed with remediation.
Status