Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug]: KafkaIO pulls dependency vulnerable to CVE-2024-26308 and CVE-2024-25710 #32675

Closed
1 of 17 tasks
stankiewicz opened this issue Oct 7, 2024 · 1 comment · Fixed by #32674
Closed
1 of 17 tasks
Assignees

Comments

@stankiewicz
Copy link
Contributor

What happened?

Add KafkaIO as dependency to pom.

https://mvnrepository.com/artifact/io.confluent/kafka-schema-registry-client/7.6.0 has 2 vulnerabilities.

There is 7.6.3 available.

Issue Priority

Priority: 2 (default / most bugs should be filed as P2)

Issue Components

  • Component: Python SDK
  • Component: Java SDK
  • Component: Go SDK
  • Component: Typescript SDK
  • Component: IO connector
  • Component: Beam YAML
  • Component: Beam examples
  • Component: Beam playground
  • Component: Beam katas
  • Component: Website
  • Component: Infrastructure
  • Component: Spark Runner
  • Component: Flink Runner
  • Component: Samza Runner
  • Component: Twister2 Runner
  • Component: Hazelcast Jet Runner
  • Component: Google Cloud Dataflow Runner
@stankiewicz
Copy link
Contributor Author

.take-issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants