You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The version of netty is the latest 4.0.x and it cannot be updated without breaking compatibility.
This component is used to connect to Cassandra and its vulnerabilities are not exploitable.
Dependency tree:
Request Type
Bug, Security
Work Environment
Problem Description
During security scanning of Docker container we detected few vulnerabilities of jars stored in /lib
/opt/thehive/lib/org.apache.htrace.htrace-core4-4.1.0-incubating.jar
CVE-2020-9547
CVE-2020-9546
CVE-2020-8840
CVE-2019-20330
CVE-2019-17531
CVE-2019-17267
CVE-2019-16943
CVE-2019-16942
CVE-2019-16335
CVE-2019-14893
CVE-2019-14892
CVE-2019-14540
CVE-2019-14379
CVE-2018-7489
CVE-2018-19362
CVE-2018-19361
CVE-2018-19360
CVE-2018-14720
CVE-2018-14719
CVE-2018-14718
/opt/thehive/lib/org.apache.htrace.htrace-core4-4.1.0-incubating.jar
/opt/thehive/lib/org.apache.tinkerpop.gremlin-shaded-3.4.6.jar
CVE-2019-20444
io.netty_netty-codec
/opt/thehive/lib/io.netty.netty-codec-4.0.56.Final.jar
CVE-2020-11112
CVE-2020-11111
CVE-2020-10969
CVE-2020-10968
CVE-2020-10673
CVE-2020-10672
/opt/thehive/lib/org.apache.htrace.htrace-core4-4.1.0-incubating.jar
/opt/thehive/lib/org.apache.tinkerpop.gremlin-shaded-3.4.6.jar
CVE-2020-36189
CVE-2020-36188
CVE-2020-36187
CVE-2020-36186
CVE-2020-36185
CVE-2020-36184
CVE-2020-36183
CVE-2020-36182
CVE-2020-36181
CVE-2020-36180
CVE-2020-36179
CVE-2020-35728
CVE-2020-35491
CVE-2020-35490
CVE-2020-24750
CVE-2020-24616
CVE-2020-14195
CVE-2020-14062
CVE-2020-14061
CVE-2020-14060
CVE-2020-11620
CVE-2020-11619
/opt/thehive/lib/org.apache.htrace.htrace-core4-4.1.0-incubating.jar
/opt/thehive/lib/org.apache.tinkerpop.gremlin-shaded-3.4.6.jar
CVE-2021-37136
CVE-2019-16869
io.netty_netty-codec
/opt/thehive/lib/io.netty.netty-codec-4.0.56.Final.jar
CVE-2021-35517
CVE-2021-35516
CVE-2021-35515
CVE-2019-14439
CVE-2019-12086
/opt/thehive/lib/org.apache.htrace.htrace-core4-4.1.0-incubating.jar
/opt/thehive/lib/org.apache.tinkerpop.gremlin-shaded-3.4.6.jar
/opt/thehive/lib/org.eclipse.jetty.jetty-io-9.4.20.v20190813.jar
Steps to Reproduce
Possible Solutions
Update version of libraries:
Complementary information
Problem with vulnerabilities also exists in newest version 4.18.
New vulnerabilities are present:
CVE-2022-25236
CVE-2022-25235
CVE-2022-23990
CVE-2022-23852
CVE-2022-22824
CVE-2022-22823
CVE-2022-22822
CVE-2022-22826
CVE-2022-22825
CVE-2021-45960
The text was updated successfully, but these errors were encountered: