[ 
https://issues.apache.org/jira/browse/KAFKA-20168?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18058157#comment-18058157
 ] 

Viktor Somogyi-Vass commented on KAFKA-20168:
---------------------------------------------

I'm currently in the process of making an RC release for 4.0.2. Did a CVE scan 
yesterday and this didn't show up. Similarly to [~chia7712] I didn't see this 
in our codebase. However, since I'm waiting for KAFKA-20131, I think we can 
merge this on 4.0.2 since it's simple, doesn't hurt to have it and we can merge 
it sooner than KAFKA-20131.

> Upgrade jetty to fix CVE-2025-5115
> ----------------------------------
>
>                 Key: KAFKA-20168
>                 URL: https://issues.apache.org/jira/browse/KAFKA-20168
>             Project: Kafka
>          Issue Type: Improvement
>            Reporter: Chia-Ping Tsai
>            Assignee: Ming-Yen Chung
>            Priority: Minor
>             Fix For: 4.3.0, 4.0.2, 4.1.2, 4.2.1, 3.9.3
>
>
> from https://lists.apache.org/thread/y0qhof032qyxvm28yvor76w13320cfs5
> https://nvd.nist.gov/vuln/detail/CVE-2025-5115



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to