Chapter 5. Fixed issues
The issues fixed in AMQ Streams 2.6 on RHEL.
For details of the issues fixed in Kafka 3.6.0, refer to the Kafka 3.6.0 Release Notes.
| Issue Number | Description |
|---|---|
| BackPort fix of ZOOKEEPER-4708 to AMQ Streams |
| Issue Number | Description |
|---|---|
| jackson-databind: denial of service via cylic dependencies | |
| CVE-2023-33201 bouncycastle: potential blind LDAP injection attack using a self-signed certificate | |
| netty: io.netty:netty-handler: SniHandler 16MB allocation | |
| CVE-2023-2976 guava: insecure temporary directory creation | |
| CVE-2023-44981 [2.6] CVE-2023-44981 zookeeper: zookeeper: Authorization Bypass in Apache ZooKeeper | |
| CVE-2023-20873 spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry | |
| CVE-2022-46751 apache-ivy: XML External Entity vulnerability | |
| CVE-2023-41080 tomcat: Open Redirect vulnerability in FORM authentication | |
| CVE-2023-40167 jetty-http: jetty: Improper validation of HTTP/1 content-length | |
| CVE-2023-42445 gradle: Possible local text file exfiltration by XML External entity injection | |
| CVE-2023-44387 gradle: Incorrect permission assignment for symlinked files used in copy or archiving operations | |
| CVE-2023-44981 zookeeper: Authorization Bypass in Apache ZooKeeper | |
| CVE-2023-31582 jose4j: Insecure iteration count setting | |
| CVE-2023-5072 in cruise-control |