Skip to content

[FP]: Quarkus mariadb for CVE-2015-2325 #8598

@kaniskavarsini

Description

@kaniskavarsini

Package URl

pkg:maven/io.quarkus/quarkus-jdbc-mariadb-deployment@3.15.4

CPE

cpe:2.3:a:mariadb:mariadb:3.15.4:::::::*

CVE

No response

ODC Integration

None

ODC Version

12.2.2

Description

CVE-2015-2325 is flagged with CPE cpe:2.3:a:mariadb:mariadb::::::::, which refers to the MariaDB database server itself.
Actual component uses pkg:maven/io.quarkus/quarkus-jdbc-mariadb-deployment@3.15.4, which is a Quarkus build-time deployment module bundles into keycloak jar by default, not the MariaDB server product.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions