Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

[Flight SQL] Derby dependency (test scope) flagged as vulnerable to CVE-2022-46337 with no available Maven patch

未關閉
#1,102 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 3 天內回覆

還沒有人認領這個 Issue。

評估

難度
5/5
預估耗時
一週以上
新手友好度
35/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
冷清
技術堆疊
java

研究方向

首先找出 flight-sql 模組中 Derby 的 Maven 相依性宣告,並檢視使用它的測試。比較升級 Derby 與將其替換為另一個嵌入式資料庫對 Java-baseline 的影響;完成的條件是 flight-sql 測試通過,且不再回報有漏洞的相依性。

由索引模型根據 Issue 內容生成。

描述

Describe the bug, including details regarding any error messages, version, and platform.

flight-sql uses org.apache.derby:derby:10.15.2.0 in test scope, which is flagged
as vulnerable to CVE-2022-46337: a critical (CVSS 9.8) LDAP authentication bypass.

There is no fix available for this dependency and there never will be.

The NVD advisory lists 10.15.2.1 as the fix for the Java 11 branch, but that
version was never published to Maven Central. The same is true for 10.14.3.0 and
10.16.1.2. The only fixed release that exists on Maven Central is 10.17.1.0
(Java 21+), which was also the last release ever made.

On 2025-10-10, the Derby PMC voted to retire the project into a read-only state.
Development and bug-fixing have ended and no further releases will be published. This
means the 10.15.x branch will remain vulnerable indefinitely with no upstream
resolution path.

Context on why the patch versions were never released:

  • DERBY-7147 — fix committed to branches, but no releases were cut for 10.14/10.15/10.16
  • DERBY-7178 — closed as "Not A Problem" by the Derby team

Since Derby is test scope only in flight-sql, there is no runtime exposure.
However, this causes persistent scanner noise for downstream consumers and the
situation will not improve on its own.

Possible paths forward:
  • Upgrade to 10.17.1.0 (requires Java 21 as test baseline for flight-sql)
  • Replace Derby with another embedded DB (e.g. H2) in flight-sql tests — likely
    the cleanest long-term option given Derby's retirement
主要語言
Java
星號
97
分支
158
平均合併
9 天 4 小時
30 天內合併 PR
13

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

apache/arrow-java 的其他 Issue

查看 apache/arrow-java 的全部 Issue

相似的 Issue

更多 Java Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。