-
-
Notifications
You must be signed in to change notification settings - Fork 223
Closed as not planned
Closed as not planned
Copy link
Labels
status/triage/completedAutomatic triage completedAutomatic triage completedstatus/triage/manualManual triage in progressManual triage in progresstype/bugSomething isn't workingSomething isn't working
Description
Issue submitter TODO list
- I've looked up my issue in FAQ
- I've searched for an already existing issues here
- I've tried running
main-labeled docker image and the issue still persists there - I'm running a supported version of the application which is listed here
Describe the bug (actual behavior)
Hi team,
We're using kafbat/kafka-ui v1.2.0 and noticed it bundles Spring Boot 3.4.3, which is affected by CVE‑2025‑22235 (high severity: RCE risk via EndpointRequest.to()).
Spring Boot fixed this in 3.4.5 — would you be able to update the dependency in the next release?
Thanks!
Expected behavior
No response
Your installation details
No
Steps to reproduce
No
Screenshots
No response
Logs
No response
Additional context
Resolve high severity issue
Metadata
Metadata
Assignees
Labels
status/triage/completedAutomatic triage completedAutomatic triage completedstatus/triage/manualManual triage in progressManual triage in progresstype/bugSomething isn't workingSomething isn't working