[
https://issues.apache.org/jira/browse/KAFKA-20168?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18058157#comment-18058157
]
Viktor Somogyi-Vass commented on KAFKA-20168:
---------------------------------------------
I'm currently in the process of making an RC release for 4.0.2. Did a CVE scan
yesterday and this didn't show up. Similarly to [~chia7712] I didn't see this
in our codebase. However, since I'm waiting for KAFKA-20131, I think we can
merge this on 4.0.2 since it's simple, doesn't hurt to have it and we can merge
it sooner than KAFKA-20131.
> Upgrade jetty to fix CVE-2025-5115
> ----------------------------------
>
> Key: KAFKA-20168
> URL: https://issues.apache.org/jira/browse/KAFKA-20168
> Project: Kafka
> Issue Type: Improvement
> Reporter: Chia-Ping Tsai
> Assignee: Ming-Yen Chung
> Priority: Minor
> Fix For: 4.3.0, 4.0.2, 4.1.2, 4.2.1, 3.9.3
>
>
> from https://lists.apache.org/thread/y0qhof032qyxvm28yvor76w13320cfs5
> https://nvd.nist.gov/vuln/detail/CVE-2025-5115
--
This message was sent by Atlassian Jira
(v8.20.10#820010)