Questo contenuto non è disponibile nella lingua selezionata.
Chapter 5. Fixed issues
The following sections list the issues fixed in AMQ Streams 2.2.x. Red Hat recommends that you upgrade to the latest patch release.
For details of the issues fixed in Kafka 3.2.0, 3.2.1, and 3.2.3, refer to the Kafka 3.2.0 Release Notes, Kafka 3.2.1 Release Notes, and Kafka 3.2.3 Release Notes.
5.1. Fixed issues for AMQ Streams 2.2.2 Copia collegamentoCollegamento copiato negli appunti!
The AMQ Streams 2.2.2 patch release (Long Term Support) is now available.
HTTP/2 DoS vulnerability (CVE-2023-44487)
The release addresses CVE-2023-44487, a critical Denial of Service (DoS) vulnerability in the HTTP/2 protocol. The vulnerability stems from mishandling multiplexed streams, allowing a malicious client to repeatedly request new streams and promptly cancel them using an RST_STREAM frame. By doing so, the attacker forces the server to expend resources setting up and tearing down streams without reaching the server-side limit for active streams per connection. For more information on this vulnerability, see the CVE-2023-44487 page for a description.
For additional details about the issues resolved in AMQ Streams 2.2.2, see AMQ Streams 2.2.x Resolved Issues.
5.2. Fixed issues for AMQ Streams 2.2.1 Copia collegamentoCollegamento copiato negli appunti!
For additional details about the issues resolved in AMQ Streams 2.2.1, see AMQ Streams 2.2.x Resolved Issues.
5.3. Fixed issues for AMQ Streams 2.2.0 Copia collegamentoCollegamento copiato negli appunti!
| Issue Number | Description |
|---|---|
| [KAFKA] MirrorMaker 2.0 negative lag | |
| [KAFKA] Unauthenticated clients may cause OutOfMemoryError on brokers |
| Issue Number | Description |
|---|---|
| CVE-2020-36518 jackson-databind: denial of service via a large depth of nested objects | |
| CVE-2022-24823 netty: world readable temporary file containing sensitive data | |
| CVE-2022-25647 com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson |