[
https://issues.apache.org/jira/browse/KAFKA-20168?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18058039#comment-18058039
]
Chia-Ping Tsai commented on KAFKA-20168:
----------------------------------------
The CVE is related to HTTP/2, and since the org.eclipse.jetty.http2 package
does not appear in our codebase, we should be safe.
> Upgrade jetty to fix CVE-2025-5115
> ----------------------------------
>
> Key: KAFKA-20168
> URL: https://issues.apache.org/jira/browse/KAFKA-20168
> Project: Kafka
> Issue Type: Improvement
> Reporter: Chia-Ping Tsai
> Assignee: Ming-Yen Chung
> Priority: Minor
>
> from https://lists.apache.org/thread/y0qhof032qyxvm28yvor76w13320cfs5
> https://nvd.nist.gov/vuln/detail/CVE-2025-5115
--
This message was sent by Atlassian Jira
(v8.20.10#820010)