-
Notifications
You must be signed in to change notification settings - Fork 415
celeborn-0.6/0.6.1-r0: cve remediation #69882
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
celeborn-0.6/0.6.1-r0: cve remediation #69882
Conversation
<!--ci-cve-scan:must-fix: GHSA-prj3-ccx8-p6x4-->
|
Creation of celeborn-0.6 package from version streaming: #69794 |
|
Upstream: https://github.com/apache/celeborn |
|
Remote scan results: |
|
Even the most recent version of ratis-thirdparty (1.0.10) is only on netty 4.1.127.Final: https://github.com/apache/ratis-thirdparty/blob/1.0.10/pom.xml (as is their tip of main). Updated to such last month: apache/ratis-thirdparty#69 |
|
Bumping ratis: apache/celeborn@b5c00ea Note radis-thirdparty version is 1.0.8, but controlled in pom.xml by ratis version of 3.1.3; most recent version 3.2.0, which has ratis-thirdparty 1.0.9: https://github.com/apache/ratis/blob/ratis-3.2.0/pom.xml -- which is set in our |
…3-ccx8-p6x4 celeborn-0.6 is newly version streamed and existing advisories under version 0.5 need to be updated for the new 0.6 version. netty is brought in by ratis, which has still not updated to a fixed version of netty. Relates: wolfi-dev/os#69882, wolfi-dev/os#69911, chainguard-dev/CVE-Dashboard#31614, chainguard-dev/CVE-Dashboard#31634, chainguard-dev/CVE-Dashboard#31623
|
Advisory PR: wolfi-dev/advisories#24367 |
* adv(celeborn-0.6): GHSA-3p8m-j85q-pgmj, GHSA-fghv-69vj-qj49, GHSA-prj3-ccx8-p6x4 celeborn-0.6 is newly version streamed and existing advisories under version 0.5 need to be updated for the new 0.6 version. netty is brought in by ratis, which has still not updated to a fixed version of netty. Relates: wolfi-dev/os#69882, wolfi-dev/os#69911, chainguard-dev/CVE-Dashboard#31614, chainguard-dev/CVE-Dashboard#31634, chainguard-dev/CVE-Dashboard#31623 * adv(celeborn-0.6): GHSA-j288-q9x7-2f5v, GHSA-h46c-h94j-95f3, GHSA-wf8f-6423-gfxg, GHSA-qh8g-58pp-2wxh, GHSA-xwmg-2g98-w7v9 celeborn-0.6 is newly version streamed and existing advisories under version 0.5 need to be updated for the new 0.6 version. hadoop is currently brought in at the most recent version (3.4.2) and all the subsequent transitive dependencies of hadoop require an upstream fix. Relates: chainguard-dev/CVE-Dashboard#31631, chainguard-dev/CVE-Dashboard#31625, chainguard-dev/CVE-Dashboard#31629, chainguard-dev/CVE-Dashboard#31627, chainguard-dev/CVE-Dashboard#31621
|
This vulnerability remediation is stale and no longer needed. 👋 Advisory CGA-83gp-5pgm-4v7j has the latest event type of "pending-upstream-fix": https://github.com/wolfi-dev/advisories/blob/main/celeborn-0.6.advisories.yaml |
celeborn-0.6/0.6.1-r0: fix GHSA-prj3-ccx8-p6x4
Advisory data: https://github.com/wolfi-dev/advisories/blob/main/celeborn-0.6.advisories.yaml
The following vulnerabilities are being deferred to future PRs (to avoid merge conflicts):
netty-codec@io.netty@netty-codec@4.1.125.Finalcommons-lang3@org.apache.commons@commons-lang3@3.18.0jetty-http@org.eclipse.jetty@jetty-http@12.0.12jackson-core@com.fasterxml.jackson.core@jackson-core@2.13.0nimbus-jose-jwt@com.nimbusds@nimbus-jose-jwt@9.37.4netty-codec-http@io.netty@netty-codec-http@4.1.125.Final"Breadcrumbs" for this automated service