/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-c453-74rv-2qcc

Published

Last updated

https://images.chainguard.dev/security/CGA-c453-74rv-2qcc
Package

druid

RepositoryWolfi
Latest Update
Fixed
Fixed Version

32.0.1-r1

Aliases
  • CVE-2022-46337
  • GHSA-rcjc-c4pj-xxrp

Severity

9.8

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-46337

Updates

Status

Fixed

Fixed version

32.0.1-r1

Status

Under investigation

Status

Fixed

Fixed version

32.0.0-r6

Status

Under investigation

Status

Fixed

Fixed version

32.0.0-r6

Status

Under investigation

Status

Fixed

Fixed version

32.0.0-r5

Status

Under investigation

Status

Fixed

Fixed version

32.0.0-r0

Status

Pending upstream fix

Impact

This vulnerability is related to 'derby', one of the dependencies of Apache druid. A fix is available, but requires upgrading 'derby' to 'v10.17.1.0'. Attempting to upgrade druid to this version results in build failures. derby v10.17.1.0 requires Java 21. Apache druid does not support currently support Java 21. Ref: https://github.com/apache/druid/blob/druid-31.0.0/docs/operations/java.md and https://db.apache.org/derby/releases/release-10_17_1_0.cgi.

Status

Under investigation

Status

Fixed

Fixed version

31.0.0-r2

Status

Pending upstream fix

Impact

This vulnerability is related to derby 10.14.2.0. Upgrading to the latest version 10.17.1.0 will fix the vulnerability, but it requires code changes in the Druid upstream repository.


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing