Questo contenuto non è disponibile nella lingua selezionata.
Chapter 5. Fixed issues
The issues fixed in AMQ Streams 2.4 on RHEL.
For details of the issues fixed in Kafka 3.4.0, refer to the Kafka 3.4.0 Release Notes.
| Issue Number | Description |
|---|---|
| [KAFKA] Mirror Maker 2 negative lag | |
| [KAFKA] MM2 connector task stopped and didn’t result in failed state | |
| [KAFKA] Confusing error in MM2 when offsets for a group cannot be synced |
| Issue Number | Description |
|---|---|
|
CVE-2022-42003 jackson-databind: deep wrapper array nesting when | |
| CVE-2022-42004 jackson-databind: use of deeply nested arrays | |
|
CVE-2023-25194: Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS | |
| CVE-2020-36518 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects | |
| CVE-2021-37137 Snappy frame decoder function doesn’t restrict the chunk length which may lead to excessive memory usage | |
| CVE-2021-37136 Bzip2 decompression decoder function doesn’t allow setting size restrictions on the decompressed output data | |
| CVE-2022-24823 Local information disclosure vulnerability in Netty | |
| CVE-2022-36944 Scala 2.13.x before 2.13.9 has a Java deserialization risk via a gadget chain | |
| CVE-2023-1370 JSON processor lib may cause stack exhaustion (stack overflow) due to recursive nesting of arrays/objects | |
|
CVE-2023-24815 Vert.x-Web apps serving files using |