io.strimzi:strimzi
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.strimzi:strimzipage 1 of 1
- CVE-2024-36543CRITICALCVSS 9.8EG 7.32024-06-17
vulnerable: 0.10.0 ... 0.9.0 (51 versions)
Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connec…
- CVE-2025-66623HIGHCVSS 7.4EG 7.4✓ Fixed in 0.49.12025-12-05
vulnerable: 0.47.0 ... 0.49.1-RC1 (7 versions)
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apach…
Check whether io.strimzi:strimzi is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.strimzi:strimzi CVEs against the assets you own.
Start Free Scan →