Skip to content

openjdk:8-jre: CRITICAL vulnerabilities found by Trivy #508

@hmarzooq

Description

@hmarzooq

Hi,

Trivy has reported below 5 CVE's as CRITICAL vulnerability on openjdk:8-jre

CVE-2021-2294, CVE-2019-8457, CVE-2022-27404, CVE-2022-1586, CVE-2022-1587. These all are from Debian side. And fortunately despite being marked as Critical, they're actually either false positive and/or categorised as Minor issue by Debian. But I've few queries here, and I would appreciate if I can get some clarification on these from openjdk:8-jre image maintainers:

1: What is the identified vulnerability is CRITICAL and is also not marked as Minor by Debian? In other words, if CVE really needs to be addressed, then what is policy from openjdk:8-jre side to get the fix from Debian? Is there a timeframe in which we can expect the fix to be reflected in openjdk:8-jre image?

2: Except CVE-2021-2294, all the remaining CVE's are shown fixed in bookworm, sid release of Debian. But I'm not able to find any openjdk-8 which is using base image from bookworm, sid release of Debian. Any advise on these lines ? As our application uses JDK8 and therefore we're bound to stick to JDK8 only. Therefore, what options we've from openjdk:8-jre image side when it comes to specific release of Debian?

Thank you!

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionUsability question, not directly related to an error with the image

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions