Package
wildfly-openjdk-21
Component
kafka-clients
Latest update
Fixed version
40.0.0-r0
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
40.0.0-r0Status
Impact
kafka-clients 3.9.2 (the fix for this CVE) introduces a transitive slf4j-api 2.0.17 dependency that is rejected by wildfly's maven-enforcer-plugin ban-transitive-deps rule. Fix gated on upstream wildfly relaxing the enforcer rule or upgrading kafka-clients with appropriate exclusions.
Status