Arushi Rai created KAFKA-15001: ---------------------------------- Summary: Medium vulnerabilities in Jetty Key: KAFKA-15001 URL: https://issues.apache.org/jira/browse/KAFKA-15001 Project: Kafka Issue Type: Task Affects Versions: 3.3.2, 3.4.0 Reporter: Arushi Rai
Kafka is using org.eclipse.jetty_jetty-server and org.eclipse.jetty_jetty-io version 9.4.48.v20220622 where 3 moderate and medium vulnerabilities have been reported. Moderate [CVE-2023-26048|https://nvd.nist.gov/vuln/detail/CVE-2023-26048] in org.eclipse.jetty_jetty-server Medium [CVE-2023-26049|https://nvd.nist.gov/vuln/detail/CVE-2023-26049] in org.eclipse.jetty_jetty-io Medium [CVE-2023-26048|https://nvd.nist.gov/vuln/detail/CVE-2023-26048] in org.eclipse.jetty_jetty-io These are fixed in jetty versions 11.0.14, 10.0.14, 9.4.51 and Kafka should use the same. -- This message was sent by Atlassian Jira (v8.20.10#820010)