[ 
https://issues.apache.org/jira/browse/KAFKA-15002?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17723925#comment-17723925
 ] 

Arushi Rai commented on KAFKA-15002:
------------------------------------

Hi [~mimaison], 

3.5.0 is upcoming release, can this vulnerability be fixed in the 3.5.0 
release? 

> Vulnerability in org.bitbucket.b_c_jose4j 
> ------------------------------------------
>
>                 Key: KAFKA-15002
>                 URL: https://issues.apache.org/jira/browse/KAFKA-15002
>             Project: Kafka
>          Issue Type: Task
>    Affects Versions: 3.4.0, 3.3.2
>            Reporter: Arushi Rai
>            Priority: Major
>
> Kafka is using package org.bitbucket.b_c_jose4j on version  0.7.9 where 
> medium vulnerability is reported 
> [GHSA-jgvc-jfgh-rjvv|https://github.com/advisories/GHSA-jgvc-jfgh-rjvv].
> Fix is available in version 0.9.3 and Kafka should look to update to the fix 
> version.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to