7.5
CVSS V3
Status
Fixed version
5.0.3-r2Status
Impact
jackson-databind 2.13.2.2 was suppressed as a CVE which can be found outlined in this issue here: https://issues.apache.org/jira/browse/CASSANDRA-17966 Though suppressed by the maintainers, the CVE is still valid.
Status
Justification
Impact
CVE considered a false positive by the maintainers: https://github.com/apache/cassandra/blob/cassandra-5.0/.build/owasp/dependency-check-suppressions.xml
Status