/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-xm7p-pr6w-92xx

Published

Last updated

https://images.chainguard.dev/security/CGA-xm7p-pr6w-92xx
Package

cassandra-reaper-jre-bcfips

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2022-1471
  • GHSA-mjmj-j48q-9wg2

Severity

9.8

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-1471

Updates

Status

Pending upstream fix

Impact

To fix the CVE we should bump the 'snakeyaml' dependency to '2.0' or higher but we cannot do that because the project does not work due to this error 'java.lang.NoSuchMethodError: void org.yaml.snakeyaml.parser.ParserImpl.<init>(org.yaml.snakeyaml.reader.StreamReader)'. There is an also an open PR about the CVE in the 'snakeyaml': https://github.com/thelastpickle/cassandra-reaper/pull/1455

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing