Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities || Upgrading Kafka connect base image || CVE #335

Open
kandukurihemanth opened this issue Jun 21, 2024 · 2 comments
Open

Comments

@kandukurihemanth
Copy link

Hello Team,

I wanted to inform you that we've recently updated our Kafka connector base image to confluentinc/cp-kafka-connect-base:7.2.10, which successfully addressed several security vulnerabilities. However, we've identified that a few critical vulnerabilities still remain unresolved in this version. Additionally, upon reviewing the latest version, 7.6.1, it appears that there are even more vulnerabilities present.

Could you please advise if there is a newer version available that resolves these remaining vulnerabilities?

@aonamrata
Copy link

😢 yea, we just updated all our connectors last month to resolve most of the vulnerabilities and now we got new ones

CVE-2023-51775 - org.bitbucket.b_c:jose4j, org.bitbucket.b_c:jose4j 
CVE-2024-29025 -  io.netty:netty-codec-http, io.netty:netty-codec-http and 2 more
CVE-2023-3894 - com.fasterxml.jackson.dataformat:jackson-dataformat-properties, com.fasterxml.jackson.dataformat:jackson-dataformat-properties
CVE-2024-21634 - software.amazon.ion:ion-java, software.amazon.ion:ion-java and 1 more

https://support.confluent.io/hc/en-us/articles/13082992005396-Confluent-Security-Advisory-CONFSA-Publication-Policy says High (CVSS ​​7.0 - 8.9) - Fix available in 30 days so 🤞

@janjwerner-confluent
Copy link
Member

Hi @kandukurihemanth and @aonamrata
New version of cp-kafka-connect-base has been released.
There are also updated version of connectors. Please update to the latest version of container image and the connectors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants