[ 
https://issues.apache.org/jira/browse/FLINK-39148?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18060684#comment-18060684
 ] 

Shekhar Prasad Rajak commented on FLINK-39148:
----------------------------------------------

Please assign to me, if I can pick it up . 

> Update flink-connector-kafka & flink-sql-connector-kafka to 4.0.1-2.0
> ---------------------------------------------------------------------
>
>                 Key: FLINK-39148
>                 URL: https://issues.apache.org/jira/browse/FLINK-39148
>             Project: Flink
>          Issue Type: Improvement
>            Reporter: Cameron
>            Priority: Major
>
> flink-connector-kafka 3.0.0-1.17 contains the following CVEs:
>  * [CVE-2025-27819|https://github.com/advisories/GHSA-mcwh-c9pg-xw43]
>  * [CVE-2025-27818|https://github.com/advisories/GHSA-76qp-h5mr-frr4]
>  * [CVE-2025-27817|https://github.com/advisories/GHSA-vgq5-3255-v292]
>  * [CVE-2024-56128|https://github.com/advisories/GHSA-p7c9-8xx8-h74f]
>  * [CVE-2024-31141|https://github.com/advisories/GHSA-2x2g-32r7-p4x8]
>  * [CVE-2023-44981|https://github.com/advisories/GHSA-7286-pgfv-vxvh]
> Upgrading to 4.0.1-2.0 resolves all above CVEs



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to