Druid container 25.0 image Critical/High Security Vulnerabilities
- Dominant language
- Java
- Stars
- 14.1k
- Forks
- 3.8k
- Avg merge
- 2d 58m
- Merged PRs (30d)
- 233
Description
Folks,
Our company recently detected around 1400+ critical vulnerabilities related to the "org.mortbay.jetty:jetty-util" (Package type Java) package vulnerability which needs to be upgraded from 6.1.26 to 9.4.47 to remediate. Below is a list of all high/critical vulnerabilities discovered
org.mortbay.jetty:jetty-util -> Upgrade from 6.1.26 to 9.4.47
See CVE-2022-2048 for more details
org.apache.velocity:velocity-engine-core -> Upgrade from 2.2 to 2.3
See CVE-2020-13936 for more details
org.yaml:snakeyaml -> upgrade from 1.27 to 1.31
See CVE-2022-25857 for more details
### Affected Version
25.0.0
### Description
Please include as much detailed information about the problem as possible.
- Deployed docker container 25.0.0 to our onprem kubernetes environment
- Ran blackduck scan to verify vulnerabilities
- Generated report which contains vulnerabilities
Contributor guide
Research direction
Start by locating the dependency declarations used to build the Druid 25.0.0 container and check how jetty-util, velocity-engine-core, and snakeyaml are brought in. Review compatibility implications of the requested versions, rebuild the container, and rerun the Black Duck scan; done means the reported high and critical vulnerabilities are remediated without breaking the build or tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, java
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100