aonamrata opened a new issue, #1612:
URL: https://github.com/apache/camel-kafka-connector/issues/1612

   Hello,
   
   We just updated 
[camel-aws-ddb-sink-kafka-connector](https://repo1.maven.org/maven2/org/apache/camel/kafkaconnector/camel-aws-ddb-sink-kafka-connector/3.21.0/camel-aws-ddb-sink-kafka-connector-3.21.0-package.tar.gz)
 connector to 3.21.0 and that resolved some security vulnerabilities but now 
there are still a few high priority ones that are open.
   
   High [CVE-2022-3509](https://nvd.nist.gov/vuln/detail/CVE-2022-3509), 
CVE-2022-3510 - com.google.protobuf:protobuf-java - Fixed version 3.21.7
   High 
[GHSA-xpw8-rcwv-8f8p](https://github.com/advisories/GHSA-xpw8-rcwv-8f8p) - 
io.netty:netty-codec-http2  - Fixed version 4.1.100.Final
   High [CVE-2023-3635](https://nvd.nist.gov/vuln/detail/CVE-2023-3635) - 
com.squareup.okio:okio - Fixed version 3.4.0
   High [CVE-2023-39410](https://nvd.nist.gov/vuln/detail/CVE-2023-39410) - 
org.apache.avro:avro  - Fixed version 1.11.3
   High [CVE-2023-44487](https://nvd.nist.gov/vuln/detail/CVE-2023-44487) - 
io.netty:netty-codec-http2  - Fixed version 4.1.100.Final
   
   Is there a version that has this resolved? Do you think these can be updated?


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscr...@camel.apache.org.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org

Reply via email to