Skip to content

Commit 8cb1040

Browse files
authored
[fix][sec] Override kafka-clients in kinesis-kpl-shaded to remediate CVE-2024-31141 and CVE-2025-27817 (#24935)
1 parent 1dfe07e commit 8cb1040

File tree

1 file changed

+6
-0
lines changed
  • pulsar-io/kinesis-kpl-shaded

1 file changed

+6
-0
lines changed

pulsar-io/kinesis-kpl-shaded/pom.xml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,12 @@
5353
<type>pom</type>
5454
<scope>import</scope>
5555
</dependency>
56+
<!-- enforce kafka client version that gets pulled transitively -->
57+
<dependency>
58+
<groupId>org.apache.kafka</groupId>
59+
<artifactId>kafka-clients</artifactId>
60+
<version>${kafka-client.version}</version>
61+
</dependency>
5662
</dependencies>
5763
</dependencyManagement>
5864
<dependencies>

0 commit comments

Comments
 (0)