Chapter 6. Fixed issues
The issues fixed in Streams for Apache Kafka 2.8 on RHEL.
For details of the issues fixed in Kafka 3.8.0, refer to the Kafka 3.8.0 Release Notes.
| Issue Number | Description |
|---|---|
| CVE-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers | |
| CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader | |
| CVE-2024-9823 org.eclipse.jetty/jetty-servlets: Jetty DOS vulnerability on DosFilter [amq-st-2] | |
| CVE-2024-8184 org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks [amq-st-2] |
Security updates
Check the latest information about Streams for Apache Kafka security updates in the Red Hat Product Advisories portal.
Erratas
Check the latest security and product enhancement advisories for Streams for Apache Kafka.