Chapter 8. Fixed issues


The issues fixed in Streams for Apache Kafka 2.8 on OpenShift.

For details of the issues fixed in Kafka 3.8.0, refer to the Kafka 3.8.0 Release Notes.

Expand
Table 8.1. Streams for Apache Kafka fixed issues
Issue numberDescription

ENTMQST-6403

Wrong keystore password error in re-built image

ENTMQST-6341

Topic Operator replication factor changes seem to conflict with Cruise Control rebalancing

ENTMQST-6257

Additional Volumes in Pod

ENTMQST-6225

The correct pod might not be restarted during PVC resizing

ENTMQST-6205

Unnecessary CA replacement run with custom CA

ENTMQST-6183

Add support for Kafka 3.8

ENTMQST-6129

Continuously generating secrets in the Kafka instance namespace on OCP 4.16

ENTMQST-6032

Logging update does not effect for controllers until rolled manually

ENTMQST-5915

Promote the UseKRaft feature gate to GA

ENTMQST-5865

Duplicate volume IDs in JBOD storage cause Pod creation errors

ENTMQST-5863

Logging configuration is never updated for Connect when connector operator is disabled

ENTMQST-5850

MM2 connector auto-restarting does not seem to work

ENTMQST-5843

Wrong parsing of SSL principal in Strimzi Quotas plugin

ENTMQST-5789

Promote KafkaNodePools feature gate to GA

ENTMQST-5740

RF Change

ENTMQST-5674

JBOD support in KRaft mode

ENTMQST-5669

Should manual rolling update failure fail the whole reconciliation?

ENTMQST-5199

Allow declarative configuration of the default user quotas

ENTMQST-4019

Remove Bidirectional TO and ZooKeeper use from TO

ENTMQST-3288

Improvements to Quotas support

ENTMQST-2632

Notifications and alerting when the user operator managed certificates are close to expiry

Expand
Table 8.2. Streams for Apache Kafka Console fixed issues
Issue numberDescription

ASUI-91

Console operator deployment name too general

Expand
Table 8.3. Streams for Apache Kafka Proxy fixed issues
Issue numberDescription

ENTMQSTPR-43

Record Encryption does not use new key material resulting from a rotation to encrypt newly produced records

Expand
Table 8.4. Fixed common vulnerabilities and exposures (CVEs)
Issue NumberDescription

ENTMQST-6422

CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers

ENTMQST-6421

CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

ENTMQST-6396

CVE-2024-9823 org.eclipse.jetty/jetty-servlets: Jetty DOS vulnerability on DosFilter [amq-st-2]

ENTMQST-6395

CVE-2024-8184 org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks [amq-st-2]

ENTMQST-6288

CVE-2024-8285 io.kroxylicious-kroxylicious-parent: Missing upstream Kafka TLS hostname verification [amq-st-2]

Security updates

Check the latest information about Streams for Apache Kafka security updates in the Red Hat Product Advisories portal.

Erratas

Check the latest security and product enhancement advisories for Streams for Apache Kafka.

Back to top
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2025 Red Hat