Chapter 6. Fixed issues


The issues fixed in Streams for Apache Kafka 2.8 on RHEL.

For details of the issues fixed in Kafka 3.8.0, refer to the Kafka 3.8.0 Release Notes.

Expand
Table 6.1. Fixed common vulnerabilities and exposures (CVEs)
Issue NumberDescription

ENTMQST-6422

CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers

ENTMQST-6421

CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

ENTMQST-6396

CVE-2024-9823 org.eclipse.jetty/jetty-servlets: Jetty DOS vulnerability on DosFilter [amq-st-2]

ENTMQST-6395

CVE-2024-8184 org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks [amq-st-2]

Security updates

Check the latest information about Streams for Apache Kafka security updates in the Red Hat Product Advisories portal.

Erratas

Check the latest security and product enhancement advisories for Streams for Apache Kafka.

Back to top
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2025 Red Hat