# CVE-2022-0778 vulnerability in liquibase

**URL:** https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731
**Category:** Uncategorized
**Created:** [April 7, 2022, 7:15pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731 "2022-04-07T19:15:08Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![trusty](https://avatars.discourse-cdn.com/v4/letter/t/5e9695/32.png) [@trusty](https://forum.liquibase.org/u/trusty)
#### Post date: [April 7, 2022, 7:15pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/1 "2022-04-07T19:15:08Z")

</div>

Hello liquibase,

Anchore has started to fail my CI/CD build due to the following vulnerability it is finding in liquibase:4.9.1:  
[https://nvd.nist.gov/vuln/detail/CVE-2022-0778](https://nvd.nist.gov/vuln/detail/CVE-2022-0778)

According to the Anchore report, it can be fixed with an upgrade:  
HIGH Vulnerability found in os package type (dpkg) - libssl1.1 (fixed in: 1.1.1d-0+deb10u8)(CVE-2022-0778 - [CVE-2022-0778](https://security-tracker.debian.org/tracker/CVE-2022-0778))

Apologies if you are already aware of this…

Thanks,

Steve

---

<div class="post-metadata">

### Author: ![tabbyfoo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/tabbyfoo/32/748_2.png) [@tabbyfoo](https://forum.liquibase.org/u/tabbyfoo)
#### Post date: [April 11, 2022, 12:35pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/2 "2022-04-11T12:35:42Z")

</div>

Welcome to the Liquibase Community, @trusty! Thanks for sharing this info - I will pass it along to our security team.

Kindly,  
Tabby

---

<div class="post-metadata">

### Author: ![ktaggart](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/ktaggart/32/596_2.png) [@ktaggart](https://forum.liquibase.org/u/ktaggart)
#### Post date: [April 11, 2022, 1:05pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/3 "2022-04-11T13:05:46Z")

</div>

Thanks @trusty. You may want to also check with Anchore because I noted that NIST reports **Undergoing Reanalysis** currently on this potential vulnerability. I am following through on this end with our security team. In the future, if you have a potential security issue, please refer to [liquibase/SECURITY.md at master · liquibase/liquibase · GitHub](https://github.com/liquibase/liquibase/blob/master/SECURITY.md) where you will find our Responsible Disclosure Policy.

---

<div class="post-metadata">

### Author: ![nvoxland](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nvoxland](https://forum.liquibase.org/u/nvoxland)
#### Post date: [April 11, 2022, 1:45pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/4 "2022-04-11T13:45:45Z")

</div>

@trusty That vulnerability seems to be more on libssl than within liquibase itself. Are you installing a deb package of liquibase? Or what liquibase artifact are you installing that your scanning is finding that vulnerability?

Thanks,  
Nathan

---

<div class="post-metadata">

### Author: ![trusty](https://avatars.discourse-cdn.com/v4/letter/t/5e9695/32.png) [@trusty](https://forum.liquibase.org/u/trusty)
#### Post date: [April 18, 2022, 3:44pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/6 "2022-04-18T15:44:28Z")

</div>

@nvoxland,  
I upgraded the liquibase artifact to 4.9.1.  
The vulnerabilities do indeed seem to originate from the kernel packages - I have had to modify the image quite a bit already to satisfy Anchore (see below). As @ktaggart suggested, I will take another look at Anchore to determine if I should more aggressively ignore their flagged vulns…

> FROM liquibase/liquibase:4.9.1
> 
> …
> 
> # CVE-2022-24407
> 
> RUN apt update
> 
> # CVE-2018-25032
> 
> RUN apt-get install -y zlib1g  
> RUN apt-get install -y libsasl2-2
> 
> # CVE-2012-3324
> 
> RUN rm -f /liquibase/lib/jcc-11.5.6.0.jar
> 
> # CVE-2021-23463
> 
> RUN rm -f /liquibase/lib/h2-1.4.200.jar
> 
> # CVE-2022-0530, CVE-2022-0529
> 
> RUN apt-get remove -y unzip
> 
> …

---

<div class="post-metadata">

### Author: ![nvoxland](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nvoxland](https://forum.liquibase.org/u/nvoxland)
#### Post date: [April 22, 2022, 1:42pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/7 "2022-04-22T13:42:55Z")

</div>

OK, thanks. We just extend our docker image from `openjdk:11-jre-slim-buster` which has it’s own update process. We don’t try to mange what comes on that base image.

The jcc and h2 drivers are added by us, but we ship h2 version 2.1.210 not the 1.4.200 version listed. I’m not sure why Anchorage would be finding that. Is it somehow getting an older liquibase image?

Nathan

---

<div class="post-metadata">

### Author: ![trusty](https://avatars.discourse-cdn.com/v4/letter/t/5e9695/32.png) [@trusty](https://forum.liquibase.org/u/trusty)
#### Post date: [April 22, 2022, 4:29pm UTC](https://forum.liquibase.org/t/cve-2022-0778-vulnerability-in-liquibase/6731/8 "2022-04-22T16:29:59Z")

</div>

Hi Nathan,  
Thanks for the response.  
And apologies for the misleading code snippet.  
My script is a bit out-of-date and should be updated to reference the latest jars - they were obviously added when using a prior version of liquibase.

I take your point about not managing the openjdk - I’ll take up my beef with them. Also, the more I think about this, the less inclined I am to see this as a truly high vulnerability, since this script is a short lived process running inside a container with no access to the outside world…
