confluent-kafka-jre-bcfips
Chainguard
8.0.0.9-r0
7.5
CVSS V3
Status
Fixed version
8.0.0.9-r0Status
Impact
Due to the nature of protobuf being a transitive dependency in the confluent-kafka project, which can be seen as the only reference to protobuf in the build.gradle file is moving the protobuf package within the shared JAR: https://github.com/confluentinc/kafka/blob/03095817ba4083115063a1df964d3a290406d167/build.gradle#L1855 We must wait for the dependency to be bumped upstream.
Status