Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- Security Release Notes for CP 7.4.7
- Security Release Notes for CP 7.3.10
- Security Release Notes for CP 7.2.12
- Security Release Notes for CP 7.1.14
- Security Release Notes for CP 7.0.16
- Security Release Notes for CFK 2.8.3
- Security Release Notes for CFK 2.7.5
- Security Release Notes for CP 7.6.2
- Security Release Notes for CP 7.5.5
- Security Release Notes for CP 7.4.6
- Security Release Notes for CP 7.3.9
- Security Release Notes for CP 7.2.11
- Security Release Notes for CP 7.1.13
- Security Release Notes for CP 7.0.15
- CONFSA-2024-03: CVE-2024-22201 - Resource exhaustion in Jetty Server
- CONFSA-2024-02: CVE-2024-27309 - Zookeeper to KRaft migration could result in lack of enforcement of Kafka ACLs under specific conditions
- CONFSA-2024-01: CVE-2024-1597 - Confluent Cloud and Self-managed Connector Vulnerability: SQL Injection In Debezium PostgreSQL and JDBC Source Connectors
- Security Release Notes for CFK 2.8.2
- Security Release Notes for CFK 2.7.4
- Security Release Notes for CFK 2.6.5
- Security Release Notes for CP 7.6.1
- Security Release Notes for CP 7.5.4
- Security Release Notes for CP 7.4.5
- Security Release Notes for CP 7.3.8
- Security Release Notes for CP 7.2.10
- Security Release Notes for CP 7.1.12
- Security Release Notes for CP 7.0.14
- Security Release Notes for CP 6.2.15
- CONFSA-2023-10: CVE-2023-46604 - Confluent Platform and Confluent Cloud Vulnerability: Impacted ActiveMQ connector versions are susceptible to Remote Code Execution (RCE) vulnerability when connecting to a malicious broker
- CONFSA-2023-09: CVE-2023-44981- Confluent Platform Vulnerability: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper