datastax / pulsar-helm-chart

Apache Pulsar Helm chart
Apache License 2.0
47 stars 38 forks source link

Upgrade Keycloak to mitigate CVEs #108

Open lhotari opened 2 years ago

lhotari commented 2 years ago

There are some recent CVEs in Keycloak. It is most likely necessary to upgrade Keycloak that is provided with this Helm chart.

lhotari commented 2 years ago

newest version of Keycloak is currently 16.1.0 https://github.com/keycloak/keycloak/releases , https://www.keycloak.org/docs/latest/release_notes/

lhotari commented 2 years ago

List of Keycloak CVEs: https://www.cvedetails.com/vulnerability-list/vendor_id-25/product_id-46161/Redhat-Keycloak.html

lhotari commented 2 years ago

OpenCVE looks nicer: https://www.opencve.io/cve?vendor=redhat&product=keycloak