/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vmw3-v8q5-r6vx

Published

Last updated

https://images.chainguard.dev/security/CGA-vmw3-v8q5-r6vx
Package

cassandra-5.0

RepositoryWolfi
Latest Update
Fixed
Fixed Version

5.0.3-r2

Aliases
  • CVE-2022-42004
  • GHSA-rgv9-q543-rqg4

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-42004

Updates

Status

Fixed

Fixed version

5.0.3-r2

Status

Pending upstream fix

Impact

jackson-databind 2.13.2.2 was suppressed as a CVE which can be found outlined in this issue here: https://issues.apache.org/jira/browse/CASSANDRA-17966 Though suppressed by the maintainers, the CVE is still valid.

Status

Not affected

Justification

Vulnerable code not present

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing