Skip to content

Will CVE-2021-38153 be remediated in a spring-kafka 2.x release? #2095

Answered by artembilan
ewan-chalmers asked this question in Q&A
Discussion options

You must be logged in to vote

There is already Spring for Apache Kafka 2.8.2: https://github.com/spring-projects/spring-kafka/releases/tag/v2.8.2, which is based on kafka-clients-3.0.0 for a while.
According that CVE:

Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher

So, what do we miss, please?
The latest GA version of spring-kafka is fully covered for that CVE.

Replies: 2 comments 7 replies

Comment options

You must be logged in to vote
4 replies
@garyrussell
Comment options

@garyrussell
Comment options

@ewan-chalmers
Comment options

@garyrussell
Comment options

Answer selected by ewan-chalmers
Comment options

You must be logged in to vote
3 replies
@garyrussell
Comment options

@garyrussell
Comment options

@ewan-chalmers
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants