Vulnerabilities are being reported for kafka container images
dkirrane opened this issue · 3 comments
dkirrane commented
If we deploy the latest 7.3.x container image e.g. confluentinc/cp-kafka-connect:7.3.3
these CVEs are showing:
CVE-2023-0361
- Red Hat Update for gnutls (RHSA-2023:1569)CVE-2023-21930
- Azul Java Multiple Vulnerabilities Security Update April 2023
janjwerner-confluent commented
@dkirrane
Thank you for raising bring this up. We expect to address those in the upcoming quarterly patch release.
dkirrane commented
this looks like it's fixed now in latest pull of confluentinc/cp-kafka-connect:7.3.3
janjwerner-confluent commented
Azul Java packages will be update in Q3 2023.