apache / apache/pulsar

[Bug] gRPC version has a vulnerability CVE-2023-44487, CVE-2023-4785, CVE-2023-33953

Open
#21,788 1 comment 0 reactions 0 assignees View on GitHub
type/bug
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 14h
Merged PRs (30d)
160

Description

### Search before asking

- [X] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.

### Version

For pulsar version: `3.1.2` on branch: `branch-3.1` facing moderate vulnerability [CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487), [CVE-2023-4785](https://nvd.nist.gov/vuln/detail/CVE-2023-4785#range-9583768), [CVE-2023-33953](https://nvd.nist.gov/vuln/detail/CVE-2023-33953), related to packages:
- io.grpc:grpc-core
- io.grpc:grpc-protobuf

Below is the versions available in pulsar -
- 1.55.3

Maven Dependency

- pulsar - org.apache.pulsar 3.1.2

### Minimal reproduce step

Run Pulsar CI workflow on pulsar branch - `branch-3.1`

### What did you expect to see?

Expected to pass the `OWASP dependency check` under `Pulsar CI` workflow.

### What did you see instead?

Vulnerability
```
Error: Failed to execute goal org.owasp:dependency-check-maven:8.2.1:aggregate (default) on project pulsar:
Error:
Error: One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '7.0':
Error:
Error: grpc-core-1.37.0.jar: CVE-2023-44487(7.5), CVE-2023-4785(7.5), CVE-2023-33953(7.5)
Error: grpc-core-1.55.3.jar: CVE-2023-44487(7.5)
Error: grpc-protobuf-1.37.0.jar: CVE-2023-44487(7.5), CVE-2023-4785(7.5), CVE-2023-33953(7.5)
Error: grpc-protobuf-1.55.3.jar: CVE-2023-44487(7.5)
```

### Anything else?

_No response_

### Are you willing to submit a PR?

- [ ] I'm willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the Maven dependency declarations for grpc-core and grpc-protobuf on branch-3.1, then run the Pulsar CI workflow's OWASP dependency check. Update the affected dependency version as needed; done means the listed CVEs no longer cause the dependency check to fail.

Written by the indexing model from the issue text.

Assessment

Tech stack
grpc, java
Domain
build-system, ci-cd, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.