- 
                Notifications
    You must be signed in to change notification settings 
- Fork 340
Open
Description
Hi confluent team!
I noticed that confluentinc-kafka-connect-s3-10.0.7 recently got flagged by our vulnerability scanner just today with the critical vulnerability, CVE-2022-26612.  From a brief glance, I think the culprit is hadoop.  Apparently, they fixed this vulnerability in version 3.2.3, but I saw that the lib files still use 2.10.1.  Since this is a major version change, I understand any concern about upgrading too hastily, but I was just hoping to get an ETA on when we can get a clean version of confluentinc-kafka-connect-s3.  Our organization has a policy of remediating all critical vulnerabilities, so any update would be greatly appreciated.
Thanks, Toby
subudhiroshan, tojaroslaw, mcgrawia, nori-arthur, gleono and 3 more
Metadata
Metadata
Assignees
Labels
No labels