Re: Vulnerabilities found for jackson-databind-2.9.9.jar and guava-20.0.jar in latest Apache-kafka latest version 2.3.0

2019-09-30 Thread David Arthur
Namrata, I'll work on producing the next RC for 2.3.1 once this and a couple of patches are available. A [VOTE] email will be sent out once the next RC is ready. Thanks, David On Mon, Sep 30, 2019 at 3:16 AM namrata kokate wrote: > Thank you for the update, I would like to know when can I exp

Re: Vulnerabilities found for jackson-databind-2.9.9.jar and guava-20.0.jar in latest Apache-kafka latest version 2.3.0

2019-09-30 Thread namrata kokate
Thank you for the update, I would like to know when can I expect this release? Regards, Namrata kokate On Sat, Sep 28, 2019, 11:21 PM Matthias J. Sax wrote: > Thanks Namrata, > > I think we should fix this for upcoming 2.3.1 release. > > -Matthias > > > On 9/26/19 10:58 PM, namrata kokate wrote

Re: Vulnerabilities found for jackson-databind-2.9.9.jar and guava-20.0.jar in latest Apache-kafka latest version 2.3.0

2019-09-28 Thread Matthias J. Sax
Thanks Namrata, I think we should fix this for upcoming 2.3.1 release. -Matthias On 9/26/19 10:58 PM, namrata kokate wrote: > Hi, > > I am currently using apache kafka latest version-2.3.0 from the official > site https://kafka.apache.org/downloads, however When I deployed the binary > on the

[jira] [Created] (KAFKA-8952) Vulnerabilities found for jackson-databind-2.9.9.jar and guava-20.0.jar in latest Apache-kafka latest version 2.3.0

2019-09-26 Thread Namrata Kokate (Jira)
Namrata Kokate created KAFKA-8952: - Summary: Vulnerabilities found for jackson-databind-2.9.9.jar and guava-20.0.jar in latest Apache-kafka latest version 2.3.0 Key: KAFKA-8952 URL: https://issues.apache.org/jira

Vulnerabilities found for jackson-databind-2.9.9.jar and guava-20.0.jar in latest Apache-kafka latest version 2.3.0

2019-09-26 Thread namrata kokate
Hi, I am currently using apache kafka latest version-2.3.0 from the official site https://kafka.apache.org/downloads, however When I deployed the binary on the containers, I can see the vulnerability reported for the two jars - jackson-databind-2.9.9.jar and guava-20.0.jar I can see these vulner