Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple vulerabilities in docker confluentinc/cp-kafka-connect:7.5.1 #250

Open
lawrencemq opened this issue Oct 27, 2023 · 8 comments
Open

Comments

@lawrencemq
Copy link

  • ID Severity Package Name Package Version
  • CVE-2022-1471 critical org.yaml_snakeyaml 1.16
  • CVE-2023-44981 critical org.apache.zookeeper_zookeeper 3.6.3
  • CVE-2023-44981 critical org.apache.zookeeper_zookeeper 3.6.4
  • PRISMA-2023-0067 high com.fasterxml.jackson.core_jackson-core 2.13.5
  • PRISMA-2023-0067 high com.fasterxml.jackson.core_jackson-core 2.14.2
  • CVE-2023-5072 high org.json_json 20230227
  • CVE-2022-25857 high org.yaml_snakeyaml 1.16
  • CVE-2017-18640 high org.yaml_snakeyaml 1.16
  • CVE-2023-4586 high io.netty_netty-codec 4.1.96.Final
  • CVE-2023-4586 high io.netty_netty-codec 4.1.86.Final
  • CVE-2023-4586 high io.netty_netty-codec 4.1.89.Final
@Tester2k23
Copy link

Tester2k23 commented Oct 28, 2023

+1
same for cp-schema-registry image:7.x.x

@c3ivodujmovic
Copy link

Any updates on the timeline for fix and/or mitigations? There are criticals in the list...

@ayushkhandelwal317
Copy link

Team, please take a look at it and prioritize it. There are some critical vulnerabilities coming from confluentinc/cp-schema-registry:7.5.3 and confluentinc/cp-kafka-connect:7.5.3

@pminkov
Copy link

pminkov commented Dec 4, 2023

+1

@asanuy
Copy link

asanuy commented Dec 12, 2023

Hey folks, do you have any estimation on when these vulnerabilities will be fixed? Thank you.

@gcaragea
Copy link

Team, please take a look at this as this is putting our deployment at risk and we will likely have to look for alternatives.

@alanperius
Copy link

Any update for confluentinc/cp-kafka-connect:7.5.3 ?

@janjwerner-confluent
Copy link
Member

janjwerner-confluent commented Apr 17, 2024

Hi,
All the issues other than
PRISMA-2023-0067 high com.fasterxml.jackson.core_jackson-core 2.13.5
PRISMA-2023-0067 high com.fasterxml.jackson.core_jackson-core 2.14.2
have been addressed.
Please update to the latest Confluent Platform images.
for the up to date information please follow:
https://support.confluent.io/hc/en-us/sections/360008413952-Security-Advisories-and-Security-Release-Notes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

9 participants