/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-ph89-hj2w-8qgh

Published

Last updated

https://images.chainguard.dev/security/CGA-ph89-hj2w-8qgh
Package

webswing

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-7254
  • GHSA-735f-pc8j-v9w8

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-7254

Updates

Status

Pending upstream fix

Impact

The Webswing project is distributed as precompiled JARs and WAR files, which bundle specific versions of third-party dependencies. These dependency versions are determined and embedded upstream by Webswing maintainers. In the current release (23.2.3), several dependencies include vulnerabilities that cannot be mitigated or upgraded directly by downstream users due to the nature of the precompiled artifacts.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing