[ https://issues.apache.org/jira/browse/KAFKA-14044?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Luke Chen resolved KAFKA-14044. ------------------------------- Fix Version/s: 3.3.0 Resolution: Fixed > Upgrade Netty and Jackson for CVE fixes > --------------------------------------- > > Key: KAFKA-14044 > URL: https://issues.apache.org/jira/browse/KAFKA-14044 > Project: Kafka > Issue Type: Bug > Components: core > Affects Versions: 3.2.0 > Reporter: Thomas Cooper > Assignee: Thomas Cooper > Priority: Minor > Labels: security > Fix For: 3.3.0 > > > There are a couple of CVEs for netty and Jackson: > Netty: [CVE-2022-24823|https://www.cve.org/CVERecord?id=CVE-2022-24823] - > Fixed by upgrading to 4.1.77+ > Jackson: [CVE-2020-36518|https://www.cve.org/CVERecord?id=CVE-2020-36518] - > Fixed by upgrading to 2.13.0+ -- This message was sent by Atlassian Jira (v8.20.10#820010)