Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-4309

Clair reports false vulnerabilities in certain situations with JAR files

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not a Bug
    • Icon: Major Major
    • None
    • None
    • clair
    • False
    • None
    • False
    • Quay Hosted

      A client is uploading their images to Quay.io, they found that Clair on Quay.io is reporting false positives on their images. This is their anaylsis:

      The issue seems to be with how Clair is scanning Jars. We have this transitive dependency tree:
      
      org.apache.cxf:cxf-rt-ws-security:3.3.6 > net.sf.ehcache:ehcache:2.10.6 > com.fasterxml.jackson.core:jackson-databind:2.9.6
      
      Even though our project overrides the jackson-databind lib and sets it to 2.12.3, the scanner is picking up the ehcache has a transitive dependency on an old version of jackson-databind. That is completely wrong and is going to get a lot of false positives. It’s up to the build tool (maven, gradle, etc.) to resolve dependency versions and the version of the libs is what’s in the packaged application, not what each artifact has in their own pom files. I think this could easily be reproduced by including ehcache:2.10.6 and jackson-databind 2.12.3 in the same container and scanning it. We were able to remove the false positive security vulnerabilities in the quay.io report by excluding the ehcache dependency entirely, even with the same jackson-databind libs. We are lucky that we don’t need ehcache so excluding it won’t be an issue. However, this bug is quite concerning and makes these reports very challenging to use.
      

      Can you please check this issue and advise what can be done? Thanks!

              hdonnay Henry Donnay
              rhn-support-ibazulic Ivan Bazulic
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: