OpenJDK17镜像CVE-2022-45146漏洞修复求助
CVE-2022-45146漏洞修复求助
Prisma扫描显示当前使用的azul/zulu-openjdk-debian:17-jre-headless-latest镜像存在CVE-2022-45146漏洞,该漏洞涉及Bouncy Castle BC-FJA 1.0.2.4之前版本,漏洞详情:
"vulnerabilities": [ { "id": "CVE-2022-45146", "status": "fixed in 1.0.2.4", "cvss": 5.5, "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "description": "An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.", "severity": "medium", "packageName": "java", "packageVersion": "17.0.9", "link": "https://nvd.nist.gov/vuln/detail/CVE-2022-45146", "riskFactors": [ "Attack complexity: low", "Exploit exists - POC", "Has fix", "Medium severity" ], "impactedVersions": [ "\u003e=13.0.0" ], "publishedDate": "2022-11-21T12:30:17Z", "discoveredDate": "2024-01-19T13:40:13Z", "fixDate": "2023-12-15T11:55:32Z", "layerTime": "2024-01-17T04:39:42Z", "packagePath": "/usr/lib/jvm/zulu17-ca-amd64/bin/java", "layerInstruction": "RUN |2 ZULU_REPO_VER=1.0.0-3 ZULU_REPO_SHA256=d08d9610c093b0954c6b278ecc628736e303634331641142fa5096396201f49c /bin/sh -c apt-get -qq update \u0026\u0026 apt-get -qq -y --no-install-recommends install gnupg software-properties-common locales curl tzdata \u0026\u0026 echo \"en_US.UTF-8 UTF-8\" \u003e\u003e /etc/locale.gen \u0026\u0026 locale-gen en_US.UTF-8 \u0026\u0026 apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 0xB1998361219BD9C9 \u0026\u0026 curl -sLO https://cdn.azul.com/zulu/bin/zulu-repo_${ZULU_REPO_VER}_all.deb \u0026\u0026 echo \"${ZULU_REPO_SHA256} zulu-repo_${ZULU_REPO_VER}_all.deb\" | sha256sum --strict --check - \u0026\u0026 dpkg -i zulu-repo_${ZULU_REPO_VER}_all.deb \u0026\u0026 apt-get -qq update \u0026\u0026 echo \"Package: zulu17-*\\nPin: version 17.0.9-*\\nPin-Priority: 1001\" \u003e /etc/apt/preferences \u0026\u0026 apt-get -qq -y --no-install-recommends install zulu17-jre-headless=17.0.9-* \u0026\u0026 apt-get -qq -y purge --auto-remove gnupg software-properties-common curl \u0026\u0026 rm -rf /var/lib/apt/lists/* zulu-repo_${ZULU_REPO_VER}_all.deb # buildkit" } ]
已尝试的修复操作:
- 更换多个最新OpenJDK17镜像
- 在pom.xml中添加以下依赖:
<dependency> <groupId>org.bouncycastle</groupId> <artifactId>bctls-jdk15to18</artifactId> <version>1.77</version> <scope>runtime</scope> </dependency> <dependency> <groupId>org.bouncycastle</groupId> <artifactId>bctls-fips</artifactId> <version>1.0.18</version> </dependency> <dependency> <groupId>org.bouncycastle</groupId> <artifactId>bc-fips</artifactId> <version>1.0.2.4</version> </dependency>
上述操作后漏洞仍未修复,已在GitHub提交问题但未获得有效解决方案,恳请提供修复思路。
内容的提问来源于stack exchange,提问作者Jon
相关产品推荐
相关产品推荐

