← All tasks
javaopenzipkin/zipkin #3522Not a task: not reproduced

Update kafka-client to at-least 3.4.0 to remediate CVE-2023-25194

envgap__openzipkin__zipkin-3522

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
f012af60b39acc67ea40987588899f93081c38f3
Manifest
zipkin-collector/kafka/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

openzipkin/zipkin #3522 · read the original issue
zipkin is getting flagged in our security scans due to the presence of `org.apache.kafka:kafka-clients` which has [CVE-2023-25194](https://www.cve.org/CVERecord?id=CVE-2023-25194).



Is there any plan to upgrade kafka-clients to at least 3.4.0 to get around this?
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]