Uploaded image for project: 'Apache Drill'
  1. Apache Drill
  2. DRILL-7162

<SECURITY ISSUE> Apache Drill uses 3rd Party with Highest CVEs

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.13.0, 1.14.0, 1.15.0
    • 1.19.0
    • None
    • None

    Description

      Apache Drill uses 3rd party libraries with almost 250+ CVEs.

      Most of the CVEs are in the older version of Jetty (9.1.x) whereas the current version of Jetty is 9.4.x

      Also many of the other libraries are in EOF versions and the are not patched even in the latest release.

      This creates an issue of security when we use it in production.

      We are able to replace many older version of libraries with the latest versions with no CVEs , however many of them are not replaceable as it is and would require some changes in the source code.

      The jetty version is of the highest priority and needs migration to 9.4.x version immediately.

       

      Please look into this issue at immediate priority as it compromises with the security of the application utilizing Apache Drill.

      Attachments

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            er.ayushsharma@gmail.com Ayush Sharma
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment