[Flight SQL] Derby dependency (test scope) flagged as vulnerable to CVE-2022-46337 with no available Maven patch
維護者通常 3 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 35/100
- Issue 類型
- 缺陷
- 描述清晰度
- 基本清楚
- 活躍度
- 冷清
- 技術堆疊
- java
研究方向
首先找出 flight-sql 模組中 Derby 的 Maven 相依性宣告,並檢視使用它的測試。比較升級 Derby 與將其替換為另一個嵌入式資料庫對 Java-baseline 的影響;完成的條件是 flight-sql 測試通過,且不再回報有漏洞的相依性。
由索引模型根據 Issue 內容生成。
描述
Describe the bug, including details regarding any error messages, version, and platform.
flight-sql uses org.apache.derby:derby:10.15.2.0 in test scope, which is flagged
as vulnerable to CVE-2022-46337: a critical (CVSS 9.8) LDAP authentication bypass.
There is no fix available for this dependency and there never will be.
The NVD advisory lists 10.15.2.1 as the fix for the Java 11 branch, but that
version was never published to Maven Central. The same is true for 10.14.3.0 and
10.16.1.2. The only fixed release that exists on Maven Central is 10.17.1.0
(Java 21+), which was also the last release ever made.
On 2025-10-10, the Derby PMC voted to retire the project into a read-only state.
Development and bug-fixing have ended and no further releases will be published. This
means the 10.15.x branch will remain vulnerable indefinitely with no upstream
resolution path.
Context on why the patch versions were never released:
- DERBY-7147 — fix committed to branches, but no releases were cut for 10.14/10.15/10.16
- DERBY-7178 — closed as "Not A Problem" by the Derby team
Since Derby is test scope only in flight-sql, there is no runtime exposure.
However, this causes persistent scanner noise for downstream consumers and the
situation will not improve on its own.
Possible paths forward:
- Upgrade to
10.17.1.0(requires Java 21 as test baseline forflight-sql) - Replace Derby with another embedded DB (e.g. H2) in
flight-sqltests — likely
the cleanest long-term option given Derby's retirement
- 主要語言
- Java
- 星號
- 97
- 分支
- 158
- 平均合併
- 9 天 4 小時
- 30 天內合併 PR
- 13
環境準備
- 提供 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
apache/arrow-java 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 74/100
apache/arrow-java#1261 ·
維護者通常 3 天內回覆
-
難度 2/5 1-3 小時 新手友好度 78/100
apache/arrow-java#1236 ·
維護者通常 3 天內回覆
-
難度 2/5 1-3 小時 新手友好度 78/100
apache/arrow-java#1230 ·
維護者通常 3 天內回覆
-
Type: bug
難度 2/5 1-3 小時 新手友好度 85/100
apache/arrow-java#1205 ·
維護者通常 3 天內回覆
-
Type: bug
難度 2/5 1-3 小時 新手友好度 68/100
apache/arrow-java#1196 · 1 則留言 ·
維護者通常 3 天內回覆
查看 apache/arrow-java 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 88/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 88/100
MaikuB/flutter_appauth#683 ·
-
type: possible bug
難度 2/5 1-3 小時 新手友好度 72/100
-
難度 2/5 1-3 小時 新手友好度 88/100
-
難度 2/5 1-3 小時 新手友好度 72/100
grimmory-tools/grimmory#2850 · 1 則留言 ·
維護者通常 1 天內回覆