We use the same base images as Camunda uses for their RUN images - if you don't like vulnerabilities in the base image then rebuild the image using your preferred base image or complain to Camunda
Our main dependency is on the camunda-connect-http-client jarfile. If it contains vulnerabilities then please take that up with Camunda
We use the latest version of Java supported by the targeted release of Camunda