confluentinc / ksql-images

KSQL platform docker images
Apache License 2.0
6 stars 21 forks source link

Vulnerability issue with 5.4.11-1 kafka images CVE-2023-4911 & CVE-2023-44487 #114

Closed rahulpurohitcore closed 9 months ago

rahulpurohitcore commented 10 months ago

The following image(5.4.11-1) is vulnerable to

  1. https://scout.docker.com/vulnerabilities/id/CVE-2023-4911
  2. https://scout.docker.com/vulnerabilities/id/CVE-2023-44487

    Please provide a resolution. Can you please check if there are any insecure uses of glibc or nghttp2 packages?

janjwerner-confluent commented 9 months ago

Branch 5.4 is no longer supported. Please use branch 6.1.x - 7.5.x