Re: Jackson CVE's in Mirror Maker 2.13-2.8.2

2022-11-10 Thread Luke Chen
Hi Andrew, Kafka community will only do bug fix release for last 3 releases based on the wiki. So, there will be no newer 2.8 patch release. https://cwiki.apache.org/confluence/display/KAFKA/Time+Based+Release+Plan#TimeBasedReleasePlan-WhatIsOurEOLPolicy ? Thank you. Luke On Thu, Nov 10, 2022 at

Jackson CVE's in Mirror Maker 2.13-2.8.2

2022-11-10 Thread Andrew Pomponio
Hello Kafka Developers, I was wondering if there are any plans to back port fixes for certain CVE’s found in Mirror Maker 2.13-2.8.2. Scans of the code found the following unpatched CVE’s: * CVE-2022-42004 * CVE-2022-42003 * CVE-2020-36518 It’s my understanding that there’s going