RE: About CVE-2023-25194

2023-03-30 Thread Margaret Figura
We recently upgraded from 2.5.0 to 3.3.1. Our usage is pretty simple -- just basic pub/sub with the standard Java producer/consumer, nothing fancy. We just needed to make this one small change in our code: "The close(long, TimeUnit) method was removed from the producer, consumer and admin client

Re: About CVE-2023-25194

2023-03-29 Thread Luke Chen
Hi, This is the commit to fix the CVE: https://github.com/apache/kafka/commit/ae22ec1a0ea005664439c3f45111aa34390ecaa1 2.x upgrades to 3.x includes a major version upgrade, so it'll have some compatibility issues. Please check the notable changes for v3.0 here: https://kafka.apache.org/documentati