confluentinc / kafka-connect-jdbc

Kafka Connect connector for JDBC-compatible databases
Other
19 stars 955 forks source link

[CC-20628] Updated sqlite dependency to CVE-2023-32697 to RCE vulnerability #1345

Closed Tanish0019 closed 1 year ago

Tanish0019 commented 1 year ago

Problem

CC-20628 RCE vulnerability in SQLITE jdbc package

Solution

Upgrade package version to 3.41.2.2. This PR was already created by Jan here but it was for 10.6.x. Seeing how many customers use older versions as well and this is a critical vulnerability, I created this PR to target older branch 10.0.x

Does this solution apply anywhere else?
If yes, where?

Test Strategy

kafka-docker-playground doesn't have sqlite option available. Ran connector locally in both sink and source mode for sqlite with basic configs to test.

Testing done:

Release Plan

[CC-20628]: https://confluentinc.atlassian.net/browse/CC-20628?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ