9.8
CVSS V3
Status
Fixed version
32.0.1-r1Status
Status
Fixed version
32.0.0-r6Status
Status
Fixed version
32.0.0-r6Status
Status
Fixed version
32.0.0-r5Status
Status
Fixed version
32.0.0-r0Status
Impact
This vulnerability is related to 'derby', one of the dependencies of Apache druid. A fix is available, but requires upgrading 'derby' to 'v10.17.1.0'. Attempting to upgrade druid to this version results in build failures. derby v10.17.1.0 requires Java 21. Apache druid does not support currently support Java 21. Ref: https://github.com/apache/druid/blob/druid-31.0.0/docs/operations/java.md and https://db.apache.org/derby/releases/release-10_17_1_0.cgi.
Status
Status
Fixed version
31.0.0-r2Status
Impact
This vulnerability is related to derby 10.14.2.0. Upgrading to the latest version 10.17.1.0 will fix the vulnerability, but it requires code changes in the Druid upstream repository.