You are viewing a plain text version of this content. The canonical link for it is here.
Posted to jira@kafka.apache.org by "Daniel Urban (Jira)" <ji...@apache.org> on 2020/08/24 12:50:00 UTC

[jira] [Resolved] (KAFKA-10414) Upgrade api-util dependency - CVE-2018-1337

     [ https://issues.apache.org/jira/browse/KAFKA-10414?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Daniel Urban resolved KAFKA-10414.
----------------------------------
    Resolution: Not A Problem

api-util is only a test dependency, not an issue.

> Upgrade api-util dependency - CVE-2018-1337
> -------------------------------------------
>
>                 Key: KAFKA-10414
>                 URL: https://issues.apache.org/jira/browse/KAFKA-10414
>             Project: Kafka
>          Issue Type: Bug
>            Reporter: Daniel Urban
>            Assignee: Daniel Urban
>            Priority: Major
>
> There is a dependency on org.apache.directory.api:api-util:1.0.0, which is involved in CVE-2018-1337. The issue is fixed in api-util:1.0.2<=
> This is a transitive dependency through the apacheds libs.
> -Can be fixed by upgrading to at least version 2.0.0.AM25-
> Since api-all is also a dependency, and there is a class collision between api-all and newer version of api-util, it is better to just upgrade api-util to 1.0.2



--
This message was sent by Atlassian Jira
(v8.3.4#803005)