scylladb / scylla-cdc-source-connector

A Kafka source connector capturing Scylla CDC changes
Apache License 2.0
41 stars 17 forks source link

Kafka Connector Vulnerabilities #37

Closed ddonaghy-c closed 6 months ago

ddonaghy-c commented 1 year ago

Confluent regularly performs security scans on Confluent Hub connectors, as per Confluent’s security policy. Unfortunately this connector has been flagged as having unacceptable vulnerabilities and our policy is to escalate the connector to removal stages, unless we receive confirmation that the issues are being addressed by the partner.

I have attached the vulnerability scan. Please note that we acknowledge two exceptions for vulnerabilities raised: Partner confirms that vulnerability is a false positive Partner confirms that the issue is valid but not exploitable

Please can you urgently acknowledge receipt of this email, and as soon as possible thereafter let us know the ScyllaDB position on these vulnerabilities.

If you require further information on any of the above, please do not hesitate to get in touch.

Best regards,

Confluent CCET Team

scylladb.csv

mykaul commented 1 year ago

See https://github.com/scylladb/kafka-connect-scylladb/issues/94

avelanarius commented 6 months ago

Closing this older issue, the reported problems were already solved (notified via email) and now we have a daily vulnerability scan in the repo (that's currently passing).