[Flight SQL] Derby dependency (test scope) flagged as vulnerable to CVE-2022-46337 with no available Maven patch

Open
#1,102 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
java

Research direction

Start by locating the Maven dependency declaration for Derby in the flight-sql module and reviewing the tests that use it. Compare the Java-baseline impact of upgrading Derby with replacing it with another embedded database; done means the flight-sql tests pass and the vulnerable dependency is no longer reported.

Written by the indexing model from the issue text.

Description

Describe the bug, including details regarding any error messages, version, and platform.

flight-sql uses org.apache.derby:derby:10.15.2.0 in test scope, which is flagged
as vulnerable to CVE-2022-46337: a critical (CVSS 9.8) LDAP authentication bypass.

There is no fix available for this dependency and there never will be.

The NVD advisory lists 10.15.2.1 as the fix for the Java 11 branch, but that
version was never published to Maven Central. The same is true for 10.14.3.0 and
10.16.1.2. The only fixed release that exists on Maven Central is 10.17.1.0
(Java 21+), which was also the last release ever made.

On 2025-10-10, the Derby PMC voted to retire the project into a read-only state.
Development and bug-fixing have ended and no further releases will be published. This
means the 10.15.x branch will remain vulnerable indefinitely with no upstream
resolution path.

Context on why the patch versions were never released:

  • DERBY-7147 — fix committed to branches, but no releases were cut for 10.14/10.15/10.16
  • DERBY-7178 — closed as "Not A Problem" by the Derby team

Since Derby is test scope only in flight-sql, there is no runtime exposure.
However, this causes persistent scanner noise for downstream consumers and the
situation will not improve on its own.

Possible paths forward:
  • Upgrade to 10.17.1.0 (requires Java 21 as test baseline for flight-sql)
  • Replace Derby with another embedded DB (e.g. H2) in flight-sql tests — likely
    the cleanest long-term option given Derby's retirement
Dominant language
Java
Stars
95
Forks
154
Avg merge
2d 16h
Merged PRs (30d)
9

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/arrow-java

All issues in apache/arrow-java

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.