Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Kafka client v2.8.1 to address timing attack issue #821

Closed
marko-asplund opened this issue Jan 2, 2022 · 3 comments
Closed

Comments

@marko-asplund
Copy link

Snyk scan reports the following issue for our service that uses fs2-kafka v2.2.0

  ✗ Timing Attack [Medium Severity][https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEKAFKA-1540737] in org.apache.kafka:kafka-clients@2.8.0
    introduced by com.foo:barlib_2.13@0.1.0-SNAPSHOT > com.github.fd4s:fs2-kafka_2.13@2.2.0 > org.apache.kafka:kafka-clients@2.8.0 and 2 other path(s)
  This issue was fixed in versions: 2.8.1, 2.7.2

Looks like series/2.x branch has already upgraded to Kafka client v2.8.1, but would someone be able to cut a release with this dependency upgrade @bplommer.

@bplommer
Copy link
Member

bplommer commented Jan 2, 2022

I'll cut a new release ASAP. In the meantime, users can resolve the issue by explicitly depending on the newer version of kafka-client.

@marko-asplund
Copy link
Author

I'll cut a new release ASAP. In the meantime, users can resolve the issue by explicitly depending on the newer version of kafka-client.

Awesome - thanks @bplommer ! 🙇

@bplommer
Copy link
Member

bplommer commented Jan 8, 2022

Resolved in v1.9.0 and v2.3.0.

@bplommer bplommer closed this as completed Jan 8, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants