Skip to content

Critical Vulnerability CVE-2022-26612 #508

@tojaroslaw

Description

@tojaroslaw

Hi confluent team!

I noticed that confluentinc-kafka-connect-s3-10.0.7 recently got flagged by our vulnerability scanner just today with the critical vulnerability, CVE-2022-26612. From a brief glance, I think the culprit is hadoop. Apparently, they fixed this vulnerability in version 3.2.3, but I saw that the lib files still use 2.10.1. Since this is a major version change, I understand any concern about upgrading too hastily, but I was just hoping to get an ETA on when we can get a clean version of confluentinc-kafka-connect-s3. Our organization has a policy of remediating all critical vulnerabilities, so any update would be greatly appreciated.

Thanks, Toby

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions