jmaver-plume / kafkajs-msk-iam-authentication-mechanism

MIT License
21 stars 26 forks source link

Update AWS libraries to pick up a version of fast-xml-parser that addresses CVE-2023-34104. #37

Closed awhittier-cribl closed 1 year ago

awhittier-cribl commented 1 year ago

Hi!

We would like to update the versions of the AWS SDK to one that depends on fast-xml-parser 4.2.5 instead of 4.1.2. 4.1.2 is vulnerable to https://www.cve.org/CVERecord?id=CVE-2023-34104, while 4.2.5 is not.

I ran the simple example against an MSK cluster we have and it authenticated without any issues. If there are any other changes you'd like or steps you want me to follow, just let me know.

Thanks!

awhittier-cribl commented 1 year ago

I will be away for the week of July 10th so if there are any comments/questions/whatever feel free to leave them here and I'll check in when I'm back.