Chapter 7. Fixed issues
The issues fixed in AMQ Streams 2.4 on OpenShift.
For details of the issues fixed in Kafka 3.4.0, refer to the Kafka 3.4.0 Release Notes.
Issue Number | Description |
---|---|
Rolling update after cluster cert deletion is stuck when operationTimeout is on 30s | |
User Operator does not scale | |
Bridge raising access denied exception when missing content-type in the request | |
[KAFKA] MM2 connector task stopped and didn’t result in failed state | |
[KAFKA] Confusing error in MM2 when offsets for a group cannot be synced | |
KafkaRoller: NPEs when the Pod does not exist | |
Delete the StrimziPodSet or StatefulSet first when migrating between them | |
KafkaConnect build does not use custom repository for parent maven dependency resolution | |
Enabling metrics fails bridge startup with | |
Fix validation of the | |
HTTP client not get assigned partitions via /assignments endpoint | |
Resources should validate correctness of new configuration | |
Newly added OAuth Password Grant feature not working in Kafka Bridge | |
Sending messages with CORS enabled raises a 400 Bad request with Null body error | |
[Kafka Bridge] Producing async=true drives to OpenTelemetry spans not linked together | |
Add support to cgroups v2 in Kafka Bridge | |
Confusing Cruise Control logs when finished | |
Connector auto-restart counter does not reset back to 0 | |
Allow Kafka exporter to change the timezone | |
Kafka Exporter dashboard does not work in newer Grafana versions | |
Certificate key replacement fails when Cluster Operator crashes after the trust is established |
Issue Number | Description |
---|---|
Drain Cleaner dependency: Red Hat build of Quarkus 2.13.7 | |
Drain Cleaner dependency: Red Hat build of Quarkus 2.13.5 | |
CVE-2022-42003 CVE-2022-42003 jackson-databind: deep wrapper array nesting when | |
CVE-2022-42004 jackson-databind: use of deeply nested arrays | |
CVE-2023-25194: Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS | |
CVE-2020-36518 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects | |
CVE-2021-37137 Snappy frame decoder function doesn’t restrict the chunk length which may lead to excessive memory usage | |
CVE-2021-37136 Bzip2 decompression decoder function doesn’t allow setting size restrictions on the decompressed output data | |
CVE-2022-24823 Local information disclosure vulnerability in Netty | |
CVE-2022-36944 Scala 2.13.x before 2.13.9 has a Java deserialization risk via a gadget chain | |
CVE-2023-1370 JSON processor lib may cause stack exhaustion (stack overflow) due to recursive nesting of arrays/objects | |
CVE-2023-24815 Vert.x-Web apps serving files using |