Security Advisories and Security Release Notes
Follow this section for security advisory notifications
- Security Release Notes for CP 7.1.13
- Security Release Notes for CP 7.0.15
- CONFSA-2024-03: CVE-2024-22201 - Resource exhaustion in Jetty Server
- CONFSA-2024-02: CVE-2024-27309 - Zookeeper to KRaft migration could result in lack of enforcement of Kafka ACLs under specific conditions
- CONFSA-2024-01: CVE-2024-1597 - Confluent Cloud and Self-managed Connector Vulnerability: SQL Injection In Debezium PostgreSQL and JDBC Source Connectors
- Security Release Notes for CFK 2.8.2
- Security Release Notes for CFK 2.7.4
- Security Release Notes for CFK 2.6.5
- Security Release Notes for CP 7.6.1
- Security Release Notes for CP 7.5.4
- Security Release Notes for CP 7.4.5
- Security Release Notes for CP 7.3.8
- Security Release Notes for CP 7.2.10
- Security Release Notes for CP 7.1.12
- Security Release Notes for CP 7.0.14
- Security Release Notes for CP 6.2.15
- CONFSA-2023-10: CVE-2023-46604 - Confluent Platform and Confluent Cloud Vulnerability: Impacted ActiveMQ connector versions are susceptible to Remote Code Execution (RCE) vulnerability when connecting to a malicious broker
- CONFSA-2023-09: CVE-2023-44981- Confluent Platform Vulnerability: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
- Security Release Notes for CFK 2.7.3
- Security Release Notes for CFK 2.6.4
- Security Release Notes for CP 6.1.15
- Security Release Notes for CP 6.2.14
- Security Release Notes for CP 7.0.13
- Security Release Notes for CP 7.1.11
- Security Release Notes for CP 7.2.9
- Security Release Notes for CP 7.3.7
- Security Release Notes for CP 7.4.4
- Security Release Notes for CP 7.5.3
- CONFSA-2023-08: Confluent Platform and Confluent Cloud Vulnerability - HTTP/2 Rapid Reset Denial of Service due to improper stream cancellation in HTTP/2 protocol: CVE-2023-44487
- CONFSA-2023-07: Confluent Platform and Confluent Cloud Vulnerability - Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact: CVE-2023-43642