You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@kafka.apache.org by "Daniel Urban (Jira)" <ji...@apache.org> on 2020/08/18 14:15:00 UTC

[jira] [Created] (KAFKA-10414) Upgrade api-util dependency - CVE-2018-1337

Daniel Urban created KAFKA-10414:
------------------------------------

             Summary: Upgrade api-util dependency - CVE-2018-1337
                 Key: KAFKA-10414
                 URL: https://issues.apache.org/jira/browse/KAFKA-10414
             Project: Kafka
          Issue Type: Bug
            Reporter: Daniel Urban


There is a dependency on org.apache.directory.api:api-util:1.0.0, which is involved in CVE-2018-1337. The issue is fixed in api-util:1.0.2<=

This is a transitive dependency through the apacheds libs. Can be fixed by upgrading to at least version 2.0.0.AM25



--
This message was sent by Atlassian Jira
(v8.3.4#803005)