7.5
CVSS V3
Status
Fixed version
3.8.1-r0Status
Impact
The commons-io dependency is a transitive dependency that Is brought in under swagger-core which is currently kept under 2.14.0 due to the fact that this version and up drop support for jdk8. The repository is currently working on transitioning on making jdk11 the minimum version but is in the middle of that process and is not currently ready. Here is the PR regarding this https://github.com/apache/kafka/pull/17441 and the project status can be found here https://issues.apache.org/jira/browse/KAFKA-12894
Status