Replies: 1 comment 2 replies
-
Any CVEs issues in a Kafka release need to be addressed in the Apache Kafka project. The same applies also to Cruise Control. Strimzi only pulls their binaries. As for Apache Kafka 3.6.0, some of the fixes might be included in Kafka 3.6.1 -> we expect that to be included in Strimzi 0.41 (we expect to start working on the 0.41 release later this week). |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Bug Description
As per quay.io the strimizi kafka operator, 3
6.0 has 1 critical vulnerabilities and several high vulnerabilities .
Steps to reproduce
1.Go to quay.io/repository/strimzi/kafka?tab=tags&tag=latest-kafka-3.6.0
2. Check for the vulnerabilities
Expected behavior
No response
Strimzi version
3.6.0
Kubernetes version
1.23
Installation method
helm chart
Infrastructure
Amazon EKS
Configuration files and logs
No response
Additional context
No response
Beta Was this translation helpful? Give feedback.
All reactions