Uploaded image for project: 'Kafka'
  1. Kafka
  2. KAFKA-14988

Upgrade scalaCollectionCompact to v2.9 for CVE-2022-36944

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • None
    • 3.5.0, 3.4.1, 3.6.0
    • None
    • None

    Description

      Current version of ScalaCollectionCompact library in trunk 2.6.0 suffers from a critical CVE-2022-36944

       

      The CVE does not impact Kafka as per https://issues.apache.org/jira/browse/KAFKA-14267  (hence, not marking this as critical) and is fixed in ScalaCollectionCompact v2.9 as per https://github.com/scala/scala-collection-compat/pull/569 

      Attachments

        Activity

          People

            divijvaidya Divij Vaidya
            divijvaidya Divij Vaidya
            Luke Chen Luke Chen
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: