Hi Team, In our security scan on Dremio 25.X version, we found vulnerabilities in the following 3rd party jars as they are not updated to latest safe versions.
dremio-twill-shaded
org.elasticsearch:elasticsearch
com.google.protobuf:protobuf-java
org.codehaus.janino:janino
javax.el-3.0.1-b11
jetty-http
jetty-server
jetty-servlets
jetty-util
json-smart
libthrift
netty-3.10.6.Final-nohttp
netty-handler-4.1.68.Final
parquet-jackson
pf4j
postgresql
woodstox-core
zookeeper
Can you please let us know if the vulnerabilities are applicable? if yes, any plans to fix them