-
Notifications
You must be signed in to change notification settings - Fork 471
Description
Hi,
Trivy has reported below 5 CVE's as CRITICAL vulnerability on openjdk:8-jre
CVE-2021-2294, CVE-2019-8457, CVE-2022-27404, CVE-2022-1586, CVE-2022-1587. These all are from Debian side. And fortunately despite being marked as Critical, they're actually either false positive and/or categorised as Minor issue by Debian. But I've few queries here, and I would appreciate if I can get some clarification on these from openjdk:8-jre image maintainers:
1: What is the identified vulnerability is CRITICAL and is also not marked as Minor by Debian? In other words, if CVE really needs to be addressed, then what is policy from openjdk:8-jre side to get the fix from Debian? Is there a timeframe in which we can expect the fix to be reflected in openjdk:8-jre image?
2: Except CVE-2021-2294, all the remaining CVE's are shown fixed in bookworm, sid release of Debian. But I'm not able to find any openjdk-8 which is using base image from bookworm, sid release of Debian. Any advise on these lines ? As our application uses JDK8 and therefore we're bound to stick to JDK8 only. Therefore, what options we've from openjdk:8-jre image side when it comes to specific release of Debian?
Thank you!