Skip to content

Suppress CVE-2022-46337 related to Derby #15484

Closed
LakshSingla wants to merge 1 commit intoapache:masterfrom
LakshSingla:supress-cve-20231205
Closed

Suppress CVE-2022-46337 related to Derby #15484
LakshSingla wants to merge 1 commit intoapache:masterfrom
LakshSingla:supress-cve-20231205

Conversation

@LakshSingla
Copy link
Copy Markdown
Contributor

Suppresses CVE-2022-46337, because Druid doesn't use authentication for Derby, therefore, the CVE doesn't apply to Druid. Also, using Derby as a metadata store for Druid in production clusters isn't advisable.

@janjwerner-confluent
Copy link
Copy Markdown
Contributor

Please see:
#15447

@LakshSingla
Copy link
Copy Markdown
Contributor Author

Thanks @janjwerner-confluent. Closing it as a duplicate.

@LakshSingla LakshSingla closed this Dec 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants