Vulnerabilities reported in the cp-server-connect-base image
cijujoseph opened this issue ยท 7 comments
We are finding the following vulnerabilities (rated as HIGH by by ECR scan) in the confluentinc/cp-server-connect-base:7.4.0 image:
- CVE-2022-45688
- Remediation - upgrade your installed software packages to the proposed fixed in version and release. Update json to 20230227
-
SNYK-JAVA-ORGBITBUCKETBC-5488281
- Upgrade your installed software packages to the proposed fixed in version and release. Update jose4j to 0.9.3
There is also a few MEDIUM rated vulns:
- SNYK-JAVA-IONETTY-1042268
- CVE-2023-26048
- CVE-2023-26049
- CVE-2022-45146
- CVE-2022-30187
- CVE-2023-24815
- CVE-2020-29582
- CVE-2022-40897
@cijujoseph
Thank you for raising this issue. We are aware of those dependencies and plan to resolve them in the upcoming patch release.
similarly just to add on I'm seeing some of the same vulnerabilities on the cp-kafka-connect
7.4.0-2-ubi image
@cijujoseph Thank you for raising this issue. We are aware of those dependencies and plan to resolve them in the upcoming patch release.
๐ Hello @janjwerner-confluent is there an expected release date for that patch?
@janjwerner-confluent do you know if CVE-2022-45688
is resolved in 3.4.1 ? I can't find mentions in the release notes. Thank you ๐.
@barambani
I don't know about the update process in AK. I expect it to be resolved in CP 7.4.1
The following Vulnerabilities in confluentinc/cp-kafka-connect:latest
VULNERABILITY TITLE | SEVERITY | CVE |
---|---|---|
Red Hat Update for python3 (RHSA-2023:3591) | CRITICAL | CVE-2023-24329 |
Azul Java Multiple Vulnerabilities Security Update April 2023 | SERIOUS | CVE-2023-21930, CVE-2023-21954, CVE-2023-21967, CVE-2023-21939, CVE-2023-21937, CVE-2023-21938, CVE-2023-21968 |
I expect those to be resolved in patch release for q3 2023.