UNCLASSIFIED - NO CUI

chore(findings): opensource/hive/hive-metastore

Summary

opensource/hive/hive-metastore has 373 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=opensource/hive/hive-metastore&tag=4.0.0&branch=master

id source severity package impact workaround
GHSA-rggv-cv7r-mw98 Anchore CVE High http2-common-9.4.44.v20210927
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.9.2
GHSA-5jpm-x58v-624v Anchore CVE Medium netty-codec-http-4.1.100.Final
CVE-2023-20861 Anchore CVE Medium spring-core-5.3.21
GHSA-r978-9m6m-6gm6 Anchore CVE Medium zookeeper-3.8.3
CVE-2023-41900 Anchore CVE Medium jetty-servlet-9.4.45.v20220203
CVE-2023-41900 Anchore CVE Medium jetty-server-9.4.45.v20220203
GHSA-4g9r-vxhx-9pgx Anchore CVE High commons-compress-1.24.0
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-27.0-jre
CVE-2023-36478 Anchore CVE High jetty-servlet-9.4.45.v20220203
GHSA-h592-38cm-4ggp Anchore CVE Critical jackson-databind-2.4.0
CVE-2023-41900 Anchore CVE Medium jetty-http-9.4.45.v20220203
CVE-2022-2047 Anchore CVE Low jetty-alpn-openjdk8-client-9.4.44.v20210927
CVE-2020-12052 Anchore CVE Medium grafana-2.23.19
CVE-2022-2048 Anchore CVE High jetty-alpn-client-9.4.44.v20210927
GHSA-gvpg-vgmx-xg6w Anchore CVE Medium nimbus-jose-jwt-9.31
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-27.0-jre
CVE-2024-23944 Anchore CVE Low zookeeper-jute-3.6.2
GHSA-mvr2-9pj6-7w5j Anchore CVE Medium guava-12.0.1
CVE-2023-41900 Anchore CVE Medium jetty-alpn-java-client-9.4.44.v20210927
GHSA-m44j-cfrm-g8qc Anchore CVE Medium bcprov-jdk15on-1.70
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-12.0.1
CVE-2023-41900 Anchore CVE Medium jetty-security-9.4.45.v20220203
CVE-2020-11110 Anchore CVE Medium grafana-2.23.19
GHSA-rgv9-q543-rqg4 Anchore CVE High jackson-databind-2.4.0
CVE-2021-22144 Anchore CVE Medium elasticsearch-2.23.19
GHSA-q93h-jc49-78gg Anchore CVE Critical jackson-databind-2.4.0
GHSA-645p-88qh-w398 Anchore CVE Critical jackson-databind-2.4.0
GHSA-mmwx-rj87-vfgr Anchore CVE Medium dnsjava-3.4.0
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-27.0-jre
CVE-2022-2048 Anchore CVE High jetty-alpn-openjdk8-client-9.4.44.v20210927
CVE-2023-40167 Anchore CVE Medium jetty-alpn-openjdk8-client-9.4.44.v20210927
GHSA-xjp4-hw94-mvp5 Anchore CVE Medium commons-configuration2-2.8.0
CVE-2023-50386 Anchore CVE High solr-solrj-8.11.2
GHSA-v435-xc8x-wvr9 Anchore CVE Medium bcprov-jdk15on-1.70
GHSA-xjp4-hw94-mvp5 Anchore CVE Medium commons-configuration2-2.8.0
GHSA-4gg5-vx3j-xwc7 Anchore CVE High protobuf-java-2.5.0
GHSA-5r5r-6hpj-8gg9 Anchore CVE High jackson-databind-2.4.0
GHSA-cj7v-27pg-wf7q Anchore CVE Low jetty-http-9.4.45.v20220203
CVE-2021-39226 Anchore CVE High grafana-2.23.19
CVE-2024-23944 Anchore CVE Low zookeeper-jute-3.8.3
CVE-2022-2048 Anchore CVE High jetty-http-9.4.45.v20220203
CVE-2021-22137 Anchore CVE Medium elasticsearch-2.23.19
CVE-2020-24303 Anchore CVE Medium grafana-2.23.19
CVE-2023-36479 Anchore CVE Medium jetty-server-9.4.45.v20220203
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-27.0-jre
CVE-2017-3161 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
GHSA-8c4j-34r4-xr8g Anchore CVE High jackson-databind-2.4.0
CVE-2013-2192 Anchore CVE Low hadoop-shaded-protobuf_3_21-1.2.0
GHSA-5jpm-x58v-624v Anchore CVE Medium netty-codec-http-4.1.100.Final
CVE-2023-40167 Anchore CVE Medium jetty-server-9.4.45.v20220203
CVE-2020-9548 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-9547 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-8840 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-20330 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-17531 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-17267 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-16943 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-16942 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-16335 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-14892 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-14540 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-14379 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-7489 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-14719 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-14718 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-11307 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2017-7525 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2017-17485 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2017-15095 Twistlock CVE Critical com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2024-25638 Twistlock CVE High dnsjava_dnsjava-3.4.0
CVE-2020-10673 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2024-36114 Twistlock CVE High io.airlift_aircompressor-0.21
CVE-2021-20190 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36189 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36188 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36187 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36186 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36185 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36184 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36183 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36182 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36181 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36180 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-36179 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-35491 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-35490 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-24750 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-24616 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2020-10650 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-5968 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2022-25647 Twistlock CVE High com.google.code.gson_gson-2.8.5
PRISMA-2023-0067 Twistlock CVE High com.fasterxml.jackson.core_jackson-core-2.4.0
PRISMA-2023-0067 Twistlock CVE High com.fasterxml.jackson.core_jackson-core-2.12.7
CVE-2024-22201 Twistlock CVE High org.eclipse.jetty.http2_http2-common-9.4.44.v20210927
CVE-2023-44487 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-39410 Twistlock CVE High org.apache.avro_avro-1.9.2
CVE-2023-36478 Twistlock CVE High org.eclipse.jetty.http2_http2-hpack-9.4.44.v20210927
CVE-2023-36478 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-20860 Twistlock CVE High spring-core-5.3.21
CVE-2023-1428 Twistlock CVE High grpc-protobuf-1.51.0
CVE-2022-42004 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2022-42003 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2022-3510 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0
CVE-2022-3509 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0
CVE-2022-2048 Twistlock CVE High org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2021-22570 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0
CVE-2021-22569 Twistlock CVE High com.google.protobuf_protobuf-java-2.5.0
CVE-2020-36518 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-14439 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-12086 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-12022 Twistlock CVE High com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2023-32731 Twistlock CVE High grpc-protobuf-1.51.0
CVE-2023-2976 Twistlock CVE High guava-27.0.0.jre
CVE-2023-2976 Twistlock CVE High com.google.guava_guava-12.0.1
CVE-2023-2976 Twistlock CVE High com.google.guava_guava-22.0
CVE-2023-2976 Twistlock CVE High com.google.guava_guava-27.0-jre
CVE-2023-50298 Twistlock CVE Medium org.apache.solr_solr-solrj-8.11.2
GHSA-mmwx-rj87-vfgr Twistlock CVE Medium dnsjava_dnsjava-3.4.0
GHSA-crjg-w57m-rqqf Twistlock CVE Medium dnsjava_dnsjava-3.4.0
CVE-2024-29133 Twistlock CVE Medium org.apache.commons_commons-configuration2-2.8.0
CVE-2024-29131 Twistlock CVE Medium org.apache.commons_commons-configuration2-2.8.0
CVE-2023-20863 Twistlock CVE Medium spring-core-5.3.21
CVE-2023-20861 Twistlock CVE Medium spring-core-5.3.21
CVE-2024-30171 Twistlock CVE Medium org.bouncycastle_bcprov-jdk15on-1.70.0
CVE-2019-12814 Twistlock CVE Medium com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2019-12384 Twistlock CVE Medium com.fasterxml.jackson.core_jackson-databind-2.4.0
CVE-2018-10237 Twistlock CVE Medium com.google.guava_guava-12.0.1
CVE-2018-10237 Twistlock CVE Medium com.google.guava_guava-22.0
CVE-2022-3171 Twistlock CVE Medium com.google.protobuf_protobuf-java-2.5.0
CVE-2024-26308 Twistlock CVE Medium org.apache.commons_commons-compress-1.24.0
CVE-2024-25710 Twistlock CVE Medium org.apache.commons_commons-compress-1.24.0
PRISMA-2023-0069 Twistlock CVE Medium com.fasterxml.jackson.core_jackson-core-2.4.0
PRISMA-2023-0068 Twistlock CVE Medium com.fasterxml.jackson.core_jackson-core-2.4.0
CVE-2024-30172 Twistlock CVE Medium org.bouncycastle_bcprov-jdk15on-1.70.0
CVE-2024-29857 Twistlock CVE Medium org.bouncycastle_bcprov-jdk15on-1.70.0
CVE-2024-29025 Twistlock CVE Medium io.netty_netty-codec-http-4.1.100.Final
CVE-2023-44487 Twistlock CVE Medium org.eclipse.jetty.http2_http2-common-9.4.44.v20210927
CVE-2023-40167 Twistlock CVE Medium org.eclipse.jetty_jetty-http-9.4.45.v20220203
CVE-2023-40167 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-33201 Twistlock CVE Medium org.bouncycastle_bcprov-jdk15on-1.70.0
CVE-2023-32732 Twistlock CVE Medium grpc-protobuf-1.51.0
CVE-2023-26049 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-26048 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-26048 Twistlock CVE Medium org.eclipse.jetty_jetty-server-9.4.45.v20220203
CVE-2023-41900 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-36479 Twistlock CVE Medium org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2024-23944 Twistlock CVE Medium org.apache.zookeeper_zookeeper-3.8.3
CVE-2023-52428 Twistlock CVE Medium com.nimbusds_nimbus-jose-jwt-9.31
CVE-2023-39804 Twistlock CVE Low tar-1.30-9.el8
CVE-2021-20193 Twistlock CVE Low tar-1.30-9.el8
CVE-2020-8908 Twistlock CVE Low com.google.guava_guava-12.0.1
CVE-2020-8908 Twistlock CVE Low com.google.guava_guava-22.0
CVE-2020-8908 Twistlock CVE Low com.google.guava_guava-27.0-jre
CVE-2020-8908 Twistlock CVE Low guava-27.0.0.jre
CVE-2019-9923 Twistlock CVE Low tar-1.30-9.el8
CVE-2022-2047 Twistlock CVE Low org.eclipse.jetty_jetty-http-9.4.45.v20220203
CVE-2022-2047 Twistlock CVE Low org.eclipse.jetty_jetty-io-9.4.45.v20220203
CVE-2023-26049 Twistlock CVE Low org.eclipse.jetty_jetty-server-9.4.45.v20220203
PRISMA-2021-0055 Twistlock CVE Low commons-codec_commons-codec-1.11
639f6f1177735759703e928c14714a59 Anchore Compliance Low
c2e44319ae5b3b040044d8ae116d1c2f Anchore Compliance Low
463a9a24225c26f7a5bf3f38908e5cb3 Anchore Compliance Low
CVE-2023-20860 Anchore CVE High spring-core-5.3.21
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-27.0-jre
CVE-2023-36479 Anchore CVE Medium jetty-io-9.4.45.v20220203
GHSA-r978-9m6m-6gm6 Anchore CVE Medium zookeeper-3.8.3
CVE-2024-23944 Anchore CVE Low zookeeper-jute-3.8.3
GHSA-9w38-p64v-xpmv Anchore CVE Medium commons-configuration2-2.8.0
GHSA-57j2-w4cx-62h2 Anchore CVE High jackson-databind-2.4.0
GHSA-gvpg-vgmx-xg6w Anchore CVE Medium nimbus-jose-jwt-9.31
GHSA-rpr3-cw39-3pxh Anchore CVE High jackson-databind-2.4.0
GHSA-4265-ccf5-phj5 Anchore CVE Medium commons-compress-1.24.0
GHSA-c8hm-7hpq-7jhg Anchore CVE Critical jackson-databind-2.4.0
GHSA-gvpg-vgmx-xg6w Anchore CVE Medium nimbus-jose-jwt-9.31
CVE-2022-31130 Anchore CVE High grafana-2.23.19
GHSA-crjg-w57m-rqqf Anchore CVE Medium dnsjava-3.4.0
CVE-2019-9923 Anchore CVE Low tar-2:1.30-9.el8
CVE-2021-43815 Anchore CVE Medium grafana-2.23.19
GHSA-973x-65j7-xcf4 Anchore CVE High aircompressor-0.21
GHSA-cfxw-4h78-h7fw Anchore CVE High dnsjava-3.4.0
GHSA-cf6r-3wgc-h863 Anchore CVE High jackson-databind-2.4.0
CVE-2024-23944 Anchore CVE Low zookeeper-jute-3.8.3
CVE-2017-3162 Anchore CVE High hadoop-shaded-protobuf_3_21-1.2.0
CVE-2022-2048 Anchore CVE High jetty-io-9.4.45.v20220203
CVE-2023-36478 Anchore CVE High jetty-util-ajax-9.4.45.v20220203
CVE-2023-39804 Anchore CVE Low tar-2:1.30-9.el8
CVE-2020-13430 Anchore CVE Medium grafana-2.23.19
CVE-2018-12099 Anchore CVE Medium grafana-2.23.19
GHSA-r978-9m6m-6gm6 Anchore CVE Medium zookeeper-3.8.3
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.4.0
CVE-2019-13068 Anchore CVE Medium grafana-2.23.19
CVE-2023-46674 Anchore CVE High elasticsearch-2.23.19
GHSA-h4h5-3hr4-j3g2 Anchore CVE Medium protobuf-java-2.5.0
GHSA-4g9r-vxhx-9pgx Anchore CVE High commons-compress-1.24.0
CVE-2020-7021 Anchore CVE Medium elasticsearch-2.23.19
GHSA-fmmc-742q-jg75 Anchore CVE Critical jackson-databind-2.4.0
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.12.7.1
GHSA-mmwx-rj87-vfgr Anchore CVE Medium dnsjava-3.4.0
CVE-2023-40167 Anchore CVE Medium jetty-alpn-client-9.4.44.v20210927
CVE-2023-20863 Anchore CVE Medium spring-core-5.3.21
CVE-2023-36479 Anchore CVE Medium jetty-util-ajax-9.4.45.v20220203
GHSA-8w26-6f25-cm9x Anchore CVE High jackson-databind-2.4.0
GHSA-5ww9-j83m-q7qx Anchore CVE High jackson-databind-2.4.0
GHSA-9gph-22xh-8x98 Anchore CVE High jackson-databind-2.4.0
CVE-2023-41900 Anchore CVE Medium jetty-util-ajax-9.4.45.v20220203
GHSA-gjmw-vf9h-g25v Anchore CVE Critical jackson-databind-2.4.0
CVE-2022-2047 Anchore CVE Low jetty-alpn-client-9.4.44.v20210927
GHSA-p26g-97m4-6q7c Anchore CVE Low jetty-server-9.4.45.v20220203
GHSA-g5ww-5jh7-63cx Anchore CVE High protobuf-java-2.5.0
CVE-2023-40167 Anchore CVE Medium jetty-util-ajax-9.4.45.v20220203
CVE-2022-35957 Anchore CVE Medium grafana-2.23.19
CVE-2023-36478 Anchore CVE High jetty-io-9.4.45.v20220203
CVE-2022-2047 Anchore CVE Low jetty-server-9.4.45.v20220203
CVE-2022-21702 Anchore CVE Medium grafana-2.23.19
GHSA-vfqx-33qm-g869 Anchore CVE High jackson-databind-2.4.0
CVE-2023-36479 Anchore CVE Medium jetty-http-9.4.45.v20220203
GHSA-qxxx-2pp7-5hmx Anchore CVE Critical jackson-databind-2.4.0
CVE-2020-7020 Anchore CVE Low elasticsearch-2.23.19
CVE-2019-19499 Anchore CVE Medium grafana-2.23.19
CVE-2022-39324 Anchore CVE Low grafana-2.23.19
GHSA-xjp4-hw94-mvp5 Anchore CVE Medium commons-configuration2-2.8.0
GHSA-5jpm-x58v-624v Anchore CVE Medium netty-codec-http-4.1.100.Final
GHSA-hr8g-6v94-x4m9 Anchore CVE Medium bcprov-jdk15on-1.70
CVE-2023-36478 Anchore CVE High jetty-http-9.4.45.v20220203
CVE-2022-2047 Anchore CVE Low jetty-alpn-java-client-9.4.44.v20210927
GHSA-mmwx-rj87-vfgr Anchore CVE Medium dnsjava-3.4.0
GHSA-5949-rw7g-wx7w Anchore CVE High jackson-databind-2.4.0
CVE-2023-36479 Anchore CVE Medium jetty-security-9.4.45.v20220203
CVE-2023-36478 Anchore CVE High jetty-security-9.4.45.v20220203
GHSA-9w38-p64v-xpmv Anchore CVE Medium commons-configuration2-2.8.0
CVE-2017-3161 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
GHSA-f9xh-2qgp-cq57 Anchore CVE High jackson-databind-2.4.0
CVE-2023-41900 Anchore CVE Medium jetty-alpn-client-9.4.44.v20210927
CVE-2022-2048 Anchore CVE High jetty-alpn-java-client-9.4.44.v20210927
CVE-2024-23944 Anchore CVE Low zookeeper-jute-3.8.3
GHSA-mvr2-9pj6-7w5j Anchore CVE Medium guava-22.0
CVE-2023-31418 Anchore CVE High elasticsearch-2.23.19
CVE-2023-36478 Anchore CVE High jetty-alpn-openjdk8-client-9.4.44.v20210927
GHSA-4jrv-ppp4-jm57 Anchore CVE High gson-2.8.5
GHSA-85cw-hj65-qqv9 Anchore CVE Critical jackson-databind-2.4.0
GHSA-qppj-fm5r-hxr3 Anchore CVE Medium http2-common-9.4.44.v20210927
CVE-2018-8025 Anchore CVE High hbase-annotations-1.7.1
GHSA-r3gr-cxrf-hg25 Anchore CVE High jackson-databind-2.4.0
GHSA-4265-ccf5-phj5 Anchore CVE Medium commons-compress-1.24.0
CVE-2020-7019 Anchore CVE Medium elasticsearch-2.23.19
CVE-2022-26148 Anchore CVE Critical grafana-2.23.19
GHSA-r978-9m6m-6gm6 Anchore CVE Medium zookeeper-3.8.3
GHSA-rfx6-vp9g-rh7v Anchore CVE Critical jackson-databind-2.4.0
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.12.7.1
GHSA-9w38-p64v-xpmv Anchore CVE Medium commons-configuration2-2.8.0
GHSA-cggj-fvv3-cqwv Anchore CVE Critical jackson-databind-2.4.0
GHSA-v435-xc8x-wvr9 Anchore CVE Medium bcprov-jdk15on-1.70
CVE-2013-2192 Anchore CVE Low hadoop-shaded-protobuf_3_21-1.2.0
CVE-2023-41900 Anchore CVE Medium jetty-io-9.4.45.v20220203
CVE-2018-8025 Anchore CVE High hbase-common-1.7.1
CVE-2018-8025 Anchore CVE High hbase-client-1.7.1
CVE-2017-3162 Anchore CVE High hadoop-shaded-protobuf_3_21-1.2.0
GHSA-9w38-p64v-xpmv Anchore CVE Medium commons-configuration2-2.8.0
CVE-2017-3161 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.12.7.1
CVE-2020-12245 Anchore CVE Medium grafana-2.23.19
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.9.2
GHSA-hr8g-6v94-x4m9 Anchore CVE Medium bcprov-jdk15on-1.70
GHSA-gww7-p5w4-wrfv Anchore CVE Critical jackson-databind-2.4.0
GHSA-6fpp-rgj9-8rwc Anchore CVE Critical jackson-databind-2.4.0
GHSA-r695-7vr9-jgc2 Anchore CVE High jackson-databind-2.4.0
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.9.2
GHSA-h4h5-3hr4-j3g2 Anchore CVE Medium protobuf-java-2.5.0
GHSA-g5ww-5jh7-63cx Anchore CVE High protobuf-java-2.5.0
GHSA-4265-ccf5-phj5 Anchore CVE Medium commons-compress-1.24.0
GHSA-89qr-369f-5m5x Anchore CVE High jackson-databind-2.4.0
CVE-2023-40167 Anchore CVE Medium jetty-alpn-java-client-9.4.44.v20210927
GHSA-wgh7-54f2-x98r Anchore CVE High http2-hpack-9.4.44.v20210927
CVE-2023-40167 Anchore CVE Medium jetty-io-9.4.45.v20220203
GHSA-4g9r-vxhx-9pgx Anchore CVE High commons-compress-1.24.0
GHSA-crjg-w57m-rqqf Anchore CVE Medium dnsjava-3.4.0
CVE-2016-5001 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
CVE-2016-5001 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
CVE-2023-36478 Anchore CVE High jetty-server-9.4.45.v20220203
GHSA-qw69-rqj8-6qw8 Anchore CVE Medium jetty-server-9.4.45.v20220203
CVE-2023-50292 Anchore CVE High solr-solrj-8.11.2
GHSA-h3cw-g4mq-c5x2 Anchore CVE High jackson-databind-2.4.0
GHSA-4gg5-vx3j-xwc7 Anchore CVE High protobuf-java-2.5.0
GHSA-cjjf-94ff-43w7 Anchore CVE High jackson-databind-2.4.0
CVE-2023-36479 Anchore CVE Medium jetty-alpn-client-9.4.44.v20210927
GHSA-fqwf-pjwf-7vqv Anchore CVE High jackson-databind-2.4.0
GHSA-mx7p-6679-8g3q Anchore CVE Critical jackson-databind-2.4.0
GHSA-cfxw-4h78-h7fw Anchore CVE High dnsjava-3.4.0
CVE-2023-40167 Anchore CVE Medium jetty-security-9.4.45.v20220203
GHSA-gvpg-vgmx-xg6w Anchore CVE Medium nimbus-jose-jwt-9.31
GHSA-rhrv-645h-fjfh Anchore CVE High avro-1.9.2
CVE-2020-12458 Anchore CVE Medium grafana-2.23.19
CVE-2021-22135 Anchore CVE Medium elasticsearch-2.23.19
GHSA-w3f4-3q6j-rh82 Anchore CVE High jackson-databind-2.4.0
GHSA-cfxw-4h78-h7fw Anchore CVE High dnsjava-3.4.0
GHSA-4w82-r329-3q67 Anchore CVE Critical jackson-databind-2.4.0
CVE-2022-2048 Anchore CVE High jetty-server-9.4.45.v20220203
GHSA-wh8g-3j2c-rqj5 Anchore CVE High jackson-databind-2.4.0
CVE-2023-41900 Anchore CVE Medium jetty-alpn-openjdk8-client-9.4.44.v20210927
GHSA-8xfc-gm6g-vgpv Anchore CVE Medium bcprov-jdk15on-1.70
CVE-2023-36478 Anchore CVE High jetty-alpn-client-9.4.44.v20210927
GHSA-hmr7-m48g-48f6 Anchore CVE Medium jetty-http-9.4.45.v20220203
CVE-2023-40167 Anchore CVE Medium jetty-util-9.4.45.v20220203
CVE-2022-2047 Anchore CVE Low jetty-servlet-9.4.45.v20220203
GHSA-crjg-w57m-rqqf Anchore CVE Medium dnsjava-3.4.0
GHSA-77rm-9x9h-xj3g Anchore CVE High protobuf-java-2.5.0
CVE-2022-39307 Anchore CVE Medium grafana-2.23.19
CVE-2023-6152 Anchore CVE Medium grafana-2.23.19
GHSA-5jpm-x58v-624v Anchore CVE Medium netty-codec-http-4.1.100.Final
CVE-2023-35116 Anchore CVE Medium jackson-databind-2.12.7.1
GHSA-r978-9m6m-6gm6 Anchore CVE Medium zookeeper-3.8.3
CVE-2023-36478 Anchore CVE High jetty-util-9.4.45.v20220203
CVE-2023-40167 Anchore CVE Medium jetty-servlet-9.4.45.v20220203
CVE-2016-5001 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
GHSA-5mg8-w23w-74h3 Anchore CVE Low guava-22.0
CVE-2023-36478 Anchore CVE High jetty-alpn-java-client-9.4.44.v20210927
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-22.0
CVE-2022-2048 Anchore CVE High jetty-servlet-9.4.45.v20220203
GHSA-4g9r-vxhx-9pgx Anchore CVE High commons-compress-1.24.0
GHSA-cmfg-87vq-g5g4 Anchore CVE Medium jackson-databind-2.4.0
CVE-2018-8025 Anchore CVE High hbase-protocol-1.7.1
GHSA-cvm9-fjm9-3572 Anchore CVE High jackson-databind-2.4.0
CVE-2005-2541 Anchore CVE Medium tar-2:1.30-9.el8
GHSA-mmwx-rj87-vfgr Anchore CVE Medium dnsjava-3.4.0
GHSA-gvpg-vgmx-xg6w Anchore CVE Medium nimbus-jose-jwt-9.31
GHSA-wrvw-hg22-4m67 Anchore CVE High protobuf-java-2.5.0
GHSA-v585-23hc-c647 Anchore CVE High jackson-databind-2.4.0
CVE-2017-3161 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
CVE-2013-2192 Anchore CVE Low hadoop-shaded-protobuf_3_21-1.2.0
GHSA-xrj7-x7gp-wwqr Anchore CVE Medium solr-solrj-8.11.2
CVE-2019-7611 Anchore CVE High elasticsearch-2.23.19
CVE-2023-50291 Anchore CVE High solr-solrj-8.11.2
GHSA-h822-r4r5-v8jg Anchore CVE Critical jackson-databind-2.4.0
CVE-2017-3162 Anchore CVE High hadoop-shaded-protobuf_3_21-1.2.0
GHSA-wrvw-hg22-4m67 Anchore CVE High protobuf-java-2.5.0
GHSA-8xfc-gm6g-vgpv Anchore CVE Medium bcprov-jdk15on-1.70
CVE-2023-36479 Anchore CVE Medium jetty-util-9.4.45.v20220203
CVE-2021-20193 Anchore CVE Medium tar-2:1.30-9.el8
CVE-2023-36479 Anchore CVE Medium jetty-alpn-java-client-9.4.44.v20210927
GHSA-p43x-xfjf-5jhr Anchore CVE Critical jackson-databind-2.4.0
GHSA-4gq5-ch57-c2mg Anchore CVE Critical jackson-databind-2.4.0
GHSA-f3j5-rmmp-3fc5 Anchore CVE Critical jackson-databind-2.4.0
CVE-2022-2047 Anchore CVE Low jetty-io-9.4.45.v20220203
GHSA-jjjh-jjxp-wpff Anchore CVE High jackson-databind-2.4.0
GHSA-4265-ccf5-phj5 Anchore CVE Medium commons-compress-1.24.0
GHSA-m44j-cfrm-g8qc Anchore CVE Medium bcprov-jdk15on-1.70
CVE-2022-36062 Anchore CVE Low grafana-2.23.19
CVE-2020-27846 Anchore CVE Critical grafana-2.23.19
CVE-2016-5001 Anchore CVE Medium hadoop-shaded-protobuf_3_21-1.2.0
GHSA-m6x4-97wx-4q27 Anchore CVE High jackson-databind-2.4.0
CVE-2022-39229 Anchore CVE Medium grafana-2.23.19
GHSA-qjw2-hr98-qgfh Anchore CVE High jackson-databind-2.4.0
GHSA-gwp4-hfv6-p7hw Anchore CVE High jackson-databind-2.4.0
CVE-2013-2192 Anchore CVE Low hadoop-shaded-protobuf_3_21-1.2.0
GHSA-crjg-w57m-rqqf Anchore CVE Medium dnsjava-3.4.0
CVE-2019-15043 Anchore CVE High grafana-2.23.19
CVE-2019-7614 Anchore CVE Medium elasticsearch-2.23.19
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-12.0.1
CVE-2023-41900 Anchore CVE Medium jetty-util-9.4.45.v20220203
CVE-2023-44981 Anchore CVE Critical zookeeper-jute-3.6.2
CVE-2023-36479 Anchore CVE Medium jetty-alpn-openjdk8-client-9.4.44.v20210927
CVE-2017-3162 Anchore CVE High hadoop-shaded-protobuf_3_21-1.2.0
GHSA-xjp4-hw94-mvp5 Anchore CVE Medium commons-configuration2-2.8.0
CVE-2018-19039 Anchore CVE Medium grafana-2.23.19
GHSA-9m6f-7xcq-8vf8 Anchore CVE High jackson-databind-2.4.0
GHSA-cfxw-4h78-h7fw Anchore CVE High dnsjava-3.4.0
GHSA-77rm-9x9h-xj3g Anchore CVE High protobuf-java-2.5.0
GHSA-5jpm-x58v-624v Anchore CVE Medium netty-codec-http-4.1.100.Final
GHSA-qr7j-h6gg-jmgc Anchore CVE Critical jackson-databind-2.4.0
CVE-2023-36479 Anchore CVE Medium jetty-servlet-9.4.45.v20220203
GHSA-mph4-vhrx-mv67 Anchore CVE Medium jackson-databind-2.4.0
GHSA-7g45-4rm6-3mm3 Anchore CVE Medium guava-27.0-jre

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=opensource/hive/hive-metastore&tag=4.0.0&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by Al Fontaine
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information