[ https://issues.apache.org/jira/browse/KAFKA-15001?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Greg Harris resolved KAFKA-15001. --------------------------------- Resolution: Fixed > CVE vulnerabilities in Jetty > ----------------------------- > > Key: KAFKA-15001 > URL: https://issues.apache.org/jira/browse/KAFKA-15001 > Project: Kafka > Issue Type: Task > Affects Versions: 3.4.0, 3.3.2 > Reporter: Arushi Rai > Priority: Critical > Fix For: 3.4.2, 3.5.1 > > > Kafka is using org.eclipse.jetty_jetty-server and org.eclipse.jetty_jetty-io > version 9.4.48.v20220622 where 3 moderate and medium vulnerabilities have > been reported. > Moderate [CVE-2023-26048|https://nvd.nist.gov/vuln/detail/CVE-2023-26048] in > org.eclipse.jetty_jetty-server > Medium [CVE-2023-26049|https://nvd.nist.gov/vuln/detail/CVE-2023-26049] in > org.eclipse.jetty_jetty-io > Medium [CVE-2023-26048|https://nvd.nist.gov/vuln/detail/CVE-2023-26048] in > org.eclipse.jetty_jetty-io > These are fixed in jetty versions 11.0.14, 10.0.14, 9.4.51 and Kafka should > use the same. -- This message was sent by Atlassian Jira (v8.20.10#820010)