apache / apache/druid

Druid container 25.0 image Critical/High Security Vulnerabilities

Open
#13,827 5 comments 0 reactions 0 assignees View on GitHub
Security
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

Folks,
Our company recently detected around 1400+ critical vulnerabilities related to the "org.mortbay.jetty:jetty-util" (Package type Java) package vulnerability which needs to be upgraded from 6.1.26 to 9.4.47 to remediate. Below is a list of all high/critical vulnerabilities discovered

org.mortbay.jetty:jetty-util -> Upgrade from 6.1.26 to 9.4.47
See CVE-2022-2048 for more details

org.apache.velocity:velocity-engine-core -> Upgrade from 2.2 to 2.3
See CVE-2020-13936 for more details

org.yaml:snakeyaml -> upgrade from 1.27 to 1.31
See CVE-2022-25857 for more details

### Affected Version

25.0.0

### Description

Please include as much detailed information about the problem as possible.
- Deployed docker container 25.0.0 to our onprem kubernetes environment
- Ran blackduck scan to verify vulnerabilities
- Generated report which contains vulnerabilities

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declarations used to build the Druid 25.0.0 container and check how jetty-util, velocity-engine-core, and snakeyaml are brought in. Review compatibility implications of the requested versions, rebuild the container, and rerun the Black Duck scan; done means the reported high and critical vulnerabilities are remediated without breaking the build or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.