Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High severity vulnerabilities CVE-2024-29857 , CVE-2024-30171 and CVE-2024-30172 detected in ksql #10350

Open
bhargavyk2002 opened this issue May 22, 2024 · 0 comments

Comments

@bhargavyk2002
Copy link

Hi,
Anchore scan has detected 3 vulnerabilities from the package 'org.bouncycastle', These are being flagged as High severity even though no vulnerability score is present in NVD database.

  1. CVE-2024-29857
  2. CVE-2024-30171
  3. CVE-2024-30172

These packages are present in ksql as a dependency
org.bouncycastle:bcprov-jdk18on:jar
bouncycastle:bcpkix-jdk18on:jar

The mitigation is to upgrade to the fixed version i.e. 1.78
Are there any plans to upgrade these packages?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant