Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Vulnerabilities found in release 4.0.2 #695

Open
ricardoredondo opened this issue Nov 6, 2024 · 1 comment
Open

Critical Vulnerabilities found in release 4.0.2 #695

ricardoredondo opened this issue Nov 6, 2024 · 1 comment

Comments

@ricardoredondo
Copy link

While working with Kafdrop a few High and Critical vulnerabilities were found. Is it possible to get these vulnerabilities addressed

What vulnerabilities were found:

  • {"service_name": "kafka-monitor", "package": "com.google.protobuf:protobuf-java", "version": "4.27.2", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-7254", "Severity": "HIGH"},
  • {"service_name": "kafka-monitor", "package": "io.undertow:undertow-core", "version": "2.3.13.Final", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-5971", "Severity": "HIGH"},
  • {"service_name": "kafka-monitor", "package": "io.undertow:undertow-core", "version": "2.3.13.Final", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-6162", "Severity": "HIGH"},
  • {"service_name": "kafka-monitor", "package": "io.undertow:undertow-core", "version": "2.3.13.Final", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-7885", "Severity": "HIGH"},
  • {"service_name": "kafka-monitor", "package": "org.apache.avro:avro", "version": "1.11.3", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-47561", "Severity": "CRITICAL"},
  • {"service_name": "kafka-monitor", "package": "org.apache.commons:commons-compress", "version": "1.21", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-25710", "Severity": "HIGH"},
  • {"service_name": "kafka-monitor", "package": "org.jboss.xnio:xnio-api", "version": "3.8.8.Final", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2023-5685", "Severity": "HIGH"},
  • {"service_name": "kafka-monitor", "package": "org.springframework:spring-webmvc", "version": "6.1.10", "valid_until": "YYYY-MM-DDTHH:MM:SSZ", "VulnerabilityID": "CVE-2024-38816", "Severity": "HIGH"}

How to retrieve the list of vulnerabilities:
For this I used Trivy. Which is a popular open source security scanner for Vulnerability
Trivy installation: https://aquasecurity.github.io/trivy/v0.57/getting-started/installation/
How to run it:

Looking fw an update in this.

@Bert-R
Copy link
Collaborator

Bert-R commented Nov 8, 2024

Do you mind running the same scan on the latest snapshot build? Then we know whether it would help to release the current snapshot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants