Security vulnerabilities in Dremio 25.X

Hi Team, In our security scan on Dremio 25.X version, we found vulnerabilities in the following 3rd party jars as they are not updated to latest safe versions.

dremio-twill-shaded
org.elasticsearch:elasticsearch
com.google.protobuf:protobuf-java
org.codehaus.janino:janino
javax.el-3.0.1-b11
jetty-http
jetty-server
jetty-servlets
jetty-util
json-smart
libthrift
netty-3.10.6.Final-nohttp
netty-handler-4.1.68.Final
parquet-jackson
pf4j
postgresql
woodstox-core
zookeeper

Can you please let us know if the vulnerabilities are applicable? if yes, any plans to fix them

@abkul

We take security issues seriously here. Security | Dremio has some more information about our approach. In general, we resolve exploitable security issues within our internal security SLAs based on severity while also aiming to update other packages with vulnerabilities (that aren’t exploitable) up to date. We do our best to document package changes in the release notes as well. You can see some of the updates made in 25.0.0 and subsequent releases on the website here .