Description
There is a vulnerability (CVE-2024-29025) in the passive dependency software Netty used by Kafka, which has been fixed in version 4.1.108.Final.
There is also a vulnerability (CVE-2024-22201) in the passive dependency software Jetty, which has been fixed in version 9.4.54.v20240208.
When will Kafka upgrade the versions of Netty and Jetty to fix these two vulnerabilities?
Reference website:
Attachments
Issue Links
- links to