confluentinc / kafka-images

Confluent Docker images for Apache Kafka
Apache License 2.0
27 stars 137 forks source link

CVE-2022-2526 and other kafka images #195

Open hbisht0720 opened 1 year ago

hbisht0720 commented 1 year ago

Hi, This is regarding the different kafka images vulnerabilities we have encountered and we would like to know the plan to fix them along with any tentative timelines:

  1. cp-kafka - CVE-2022-2526
  2. cp-kafka - CVE-2022-2048
  3. cp-kafka-connect - CVE-2022-2526
  4. cp-kafka-connect - CVE-2022-2048
  5. cp-kafka-connect - CVE-2021-22573
  6. cp-kafka-connect - CVE-2022-31159
  7. cp-ksqldb-server - CVE-2022-2526
  8. cp-ksqldb-server - CVE-2022-31159
  9. cp-ksqldb-server - CVE-2021-22573
  10. cp-ksqldb-server - CVE-2022-2048
  11. cp-schema-registry - CVE-2022-2526
  12. cp-schema-registry - CVE-2022-2526
  13. cp-schema-registry - CVE-2022-2526
  14. cp-schema-registry - CVE-2022-2526
janjwerner-confluent commented 1 year ago

Hello, Thank you for bringing this to our attention. Can you please indicate which version of the images have you inspected?