Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-31761

(xp-5.0.x) Update kafka-clients dependency lz4-java to version 1.10.1.rhel8-redhat-00001

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False

      XP5 uses "kafka-clients" version 3.7.1.redhat-00001 which has lz4-java 1.8.0.redhat-00010 [1] as dependency. This version of lz4-java contains CVE-2025-66566 and we need to update it (JBEAP-31646).

      [1] https://indy.corp.redhat.com/api/content/maven/hosted/pnc-builds/org/apache/kafka/kafka-clients/3.7.1.redhat-00001/kafka-clients-3.7.1.redhat-00001.pom

              kkhan1@redhat.com Kabir Khan
              istudens@redhat.com Ivo Studensky
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: