You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenJDK17镜像CVE-2022-45146漏洞修复求助

CVE-2022-45146漏洞修复求助

Prisma扫描显示当前使用的azul/zulu-openjdk-debian:17-jre-headless-latest镜像存在CVE-2022-45146漏洞,该漏洞涉及Bouncy Castle BC-FJA 1.0.2.4之前版本,漏洞详情:

"vulnerabilities": [
            {
                "id": "CVE-2022-45146",
                "status": "fixed in 1.0.2.4",
                "cvss": 5.5,
                "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "description": "An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.",
                "severity": "medium",
                "packageName": "java",
                "packageVersion": "17.0.9",
                "link": "https://nvd.nist.gov/vuln/detail/CVE-2022-45146",
                "riskFactors": [
                    "Attack complexity: low",
                    "Exploit exists - POC",
                    "Has fix",
                    "Medium severity"
                ],
                "impactedVersions": [
                    "\u003e=13.0.0"
                ],
                "publishedDate": "2022-11-21T12:30:17Z",
                "discoveredDate": "2024-01-19T13:40:13Z",
                "fixDate": "2023-12-15T11:55:32Z",
                "layerTime": "2024-01-17T04:39:42Z",
                "packagePath": "/usr/lib/jvm/zulu17-ca-amd64/bin/java",
                "layerInstruction": "RUN |2 ZULU_REPO_VER=1.0.0-3 ZULU_REPO_SHA256=d08d9610c093b0954c6b278ecc628736e303634331641142fa5096396201f49c /bin/sh -c apt-get -qq update \u0026\u0026     apt-get -qq -y --no-install-recommends install gnupg software-properties-common locales curl tzdata \u0026\u0026     echo \"en_US.UTF-8 UTF-8\" \u003e\u003e /etc/locale.gen \u0026\u0026     locale-gen en_US.UTF-8 \u0026\u0026     apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 0xB1998361219BD9C9 \u0026\u0026     curl -sLO https://cdn.azul.com/zulu/bin/zulu-repo_${ZULU_REPO_VER}_all.deb \u0026\u0026     echo \"${ZULU_REPO_SHA256} zulu-repo_${ZULU_REPO_VER}_all.deb\" | sha256sum --strict --check - \u0026\u0026     dpkg -i zulu-repo_${ZULU_REPO_VER}_all.deb \u0026\u0026     apt-get -qq update \u0026\u0026     echo \"Package: zulu17-*\\nPin: version 17.0.9-*\\nPin-Priority: 1001\" \u003e /etc/apt/preferences \u0026\u0026     apt-get -qq -y --no-install-recommends install zulu17-jre-headless=17.0.9-* \u0026\u0026     apt-get -qq -y purge --auto-remove gnupg software-properties-common curl \u0026\u0026     rm -rf /var/lib/apt/lists/* zulu-repo_${ZULU_REPO_VER}_all.deb # buildkit"
            }
        ]

已尝试的修复操作:

  • 更换多个最新OpenJDK17镜像
  • 在pom.xml中添加以下依赖:
<dependency>
    <groupId>org.bouncycastle</groupId>
    <artifactId>bctls-jdk15to18</artifactId>
    <version>1.77</version>
    <scope>runtime</scope>
</dependency>

<dependency>
    <groupId>org.bouncycastle</groupId>
    <artifactId>bctls-fips</artifactId>
    <version>1.0.18</version>
</dependency>

<dependency>
    <groupId>org.bouncycastle</groupId>
    <artifactId>bc-fips</artifactId>
    <version>1.0.2.4</version>
</dependency>

上述操作后漏洞仍未修复,已在GitHub提交问题但未获得有效解决方案,恳请提供修复思路。

内容的提问来源于stack exchange,提问作者Jon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 19:24:52