apache / pulsar

Apache Pulsar - distributed pub-sub messaging system
https://pulsar.apache.org/
Apache License 2.0
13.93k stars 3.53k forks source link

[Security] 3.0.2 and 3.1.1 has 2 fixable security vulnerabilities. #21457

Open compuguy opened 8 months ago

compuguy commented 8 months ago

Search before asking

Version

The second candidate for v3.0.2 and release 3.1.1.

Minimal reproduce step

Used a container security scanner included with Red Hat Advanced Cluster Security for Kubernetes, Stackrox Scanner.

What did you expect to see?

Vulnerabilities that should have been fixed in 3.0.2 are showing up with the included version of Trino version 368.

What did you see instead?

Screenshot 2023-10-27 171327

Anything else?

Some of this has been mentioned in #18348 previously. Issue should not be tagged as type/bug but component/security.

Should upgrade Trino from 368 to 430, if possible.

Are you willing to submit a PR?

Technoboy- commented 8 months ago

I will try to upgrade and test.

compuguy commented 6 months ago

Just to update this issue, I'm not sure if CVE-2023-0833 is related to Pulsar. It mentions a vulnerability with Red Hat's AMQ-Streams,....