castorm/kafka-connect-http

Connector vulnerabilities

AskMeiPaaS opened this issue · 1 comments

The following vulnerabilities are identified with the connector.

CVE-2020-36518
CVE-2020-29582
CVE-2022-24329

Could you please verify it for false positive?

We regularly perform security scans on Confluent Hub connectors, as per Confluent’s security policy. Unfortunately the this connector has been flagged as having unacceptable vulnerabilities and our policy is to escalate the connector to removal stages, unless we receive confirmation that the issues are being addressed by the partner.

I have attached the vulnerability scan. Please note that we acknowledge two exceptions for vulnerabilities raised:
Partner confirms that vulnerability is a false positive
Partner confirms that the issue is valid but not exploitable

Please can you urgently acknowledge receipt of this email, and as soon as possible thereafter let us know the position on these vulnerabilities.

If you require further information on any of the above, please do not hesitate to get in touch.

Best regards,

CCET Team

castorm.csv