apache / apache/pulsar

[Security] v2.10.2 contains up to 9 year old vulnerabilities/CVEs -> get rid of the oldest

Open
#18,338 2 comments 0 reactions 0 assignees View on GitHub
Stale type/bug
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 14h
Merged PRs (30d)
160

Description

### Search before asking

- [X] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.

### Version

latest v2.10.2

### Minimal reproduce step

1. look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report

2. open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image
3. see details:

![2022-11-04_09h25_11](https://user-images.githubusercontent.com/5681880/199929443-5eb31da3-08e4-435c-ad6d-3fed4f015eb6.png)

![2022-11-04_09h21_54](https://user-images.githubusercontent.com/5681880/199929354-beb78a27-d252-40d0-8b33-1e0083df9d89.png)

### What did you expect to see?

no fixable vulnerabilities (with severity greater than low) older than some month in latest pulsar image.
At the very least, non older than 1 year

### What did you see instead?

**fixable and reported** vulnerabilities
- of severity CRITICAL with an age of 5 years
- severity MEDIUM with an age of 9 years

reports see:
https://github.com/apache/pulsar/issues/8967

### Anything else?

these old security issues are not only a security problem but may also give bad impression for the importance of security in our project
(since we are today already doing great things in this field, this may lead to a false impression)

of course it makes sense to solve all fixable vulnerabilities, but these 3 may be the most hurting ones,
and for fixing all, there is another topic..https://github.com/apache/pulsar/issues/18348

### Are you willing to submit a PR?

- [ ] I'm willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

Start with the Trivy security report for the Apache Pulsar Helm chart v3.0.0 and its included Pulsar v2.10.2 image, then review issues #8967 and #18348 for existing vulnerability context. Identify the oldest fixable vulnerabilities and their update path; done means the reported image no longer contains fixable vulnerabilities above low severity older than the stated threshold.

Written by the indexing model from the issue text.

Assessment

Tech stack
helm, java
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.