Package
apache-activemq-fips-6.2
Component
jetty-http
Latest update
3.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The jetty-http dependency at version 11.0.26 contains a vulnerability (GHSA-wjpw-4j6x-6rwh) that is fixed in Jetty 12.0.31 or 12.1.5. This is a transitive dependency brought in via upstream Apache ActiveMQ and is part of a coherent set of jetty-* artifacts that cannot be bumped independently. Resolution requires:
Status