Vulnerability found in logstash-oss:8.13.2
- Dominant language
- Java
- Stars
- 14.9k
- Forks
- 3.5k
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 88
Description
On scanning the logstash-oss:8.13.2 docker image, found the below vulnerability in it.
Type | Severity | CVSS | CVE | Package Name | Package Version | Fix Status
-- | -- | -- | -- | -- | -- | --
Jar | Critical | 9.8 | CVE-2022-46337 | derby | 10.15.2.1 | fixed in: 10.17.1.0
Jar | High | 7.1 | CVE-2023-2976 | com.google.guava_guava | 25.1-android | fixed in: 32.0.0
Product | Medium | 5.5 | CVE-2022-45146 | java | 17.0.10 | fixed in: 1.0.2.4
Jar | Moderate | 5.3 | CVE-2024-29025 | io.netty_netty-codec-http | 4.1.100.Final | fixed in: 4.1.108.Final
Jar | Medium | 4.7 | CVE-2023-35116 | com.fasterxml.jackson.core_jackson-databind | 2.15.2 | fixed in: 2.16.0
Jar | Medium | 4.7 | CVE-2023-35116 | com.fasterxml.jackson.core_jackson-databind | 2.15.3 | fixed in: 2.16.0
Package | Medium | 0 | CVE-2024-28834 | gnutls28 | 3.6.13-2ubuntu1.10 | fixed in: 3.6.13-2ubuntu1.11
Jar | Low | 3.7 | CVE-2020-9488 | org.apache.logging.log4j_log4j | 1.2-api-2 | fixed in: 2.3.2, 2.12.3, 2.13.2
Jar | Low | 3.3 | CVE-2020-8908 | com.google.guava_guava | 25.1-android | fixed in: 32.0.0
Contributor guide
Research direction
Start by reproducing the scan against the logstash-oss:8.13.2 Docker image and review the reported Java and system packages, including derby, Guava, Netty, Jackson, Log4j, gnutls28, and Java. Done means the affected components are updated to versions addressing the listed CVEs and a follow-up scan no longer reports them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, java
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100