Skip to content

[Security] v2.10.2 contains up to 9 year old vulnerabilities/CVEs -> get rid of the oldest #18338

@hpvd

Description

@hpvd

Search before asking

  • I searched in the issues and found nothing similar.

Version

latest v2.10.2

Minimal reproduce step

  1. look into trivy powered inspection for vulnerabilities
    at artifacthub.io
    https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report

  2. open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image

  3. see details:

2022-11-04_09h25_11

2022-11-04_09h21_54

What did you expect to see?

no fixable vulnerabilities (with severity greater than low) older than some month in latest pulsar image.
At the very least, non older than 1 year

What did you see instead?

fixable and reported vulnerabilities

  • of severity CRITICAL with an age of 5 years
  • severity MEDIUM with an age of 9 years

reports see:
#8967

Anything else?

these old security issues are not only a security problem but may also give bad impression for the importance of security in our project
(since we are today already doing great things in this field, this may lead to a false impression)

of course it makes sense to solve all fixable vulnerabilities, but these 3 may be the most hurting ones,
and for fixing all, there is another topic..#18348

Are you willing to submit a PR?

  • I'm willing to submit a PR!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Staletype/bugThe PR fixed a bug or issue reported a bug

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions