Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-31754

(xp-6.0.z) Update kafka-clients dependency lz4-java to version 1.10.1.rhel8-redhat-00001

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False

      XP6 uses "kafka-clients" version 3.9.1.redhat-00006 [1] which has lz4-java 1.8.0.redhat-00010 [2] as dependency. This version of lz4-java contains CVE-2025-66566 and we need to update it (JBEAP-31645).

      [1]

      • groupId: "org.apache.kafka"
        artifactId: "kafka-clients"
        version: "3.9.1.redhat-00006"

      [2] https://indy.corp.redhat.com/api/content/maven/hosted/pnc-builds/org/apache/kafka/kafka-clients/3.9.1.redhat-00006/kafka-clients-3.9.1.redhat-00006.pom

              kkhan1@redhat.com Kabir Khan
              rhn-support-ivassile Ilia Vassilev
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: