RHSA-2024:9571MediumCVSS 7.5

Red Hat Security Advisory: Streams for Apache Kafka 2.8.0 release and security update

Published
November 13, 2024
Last Modified
June 2, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-8184 — org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks CVE-2024-8285 — kroxylicious: Missing upstream Kafka TLS hostname verification CVE-2024-9823 — org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter CVE-2024-29025 — netty-codec-http: Allocation of Resources Without Limits or Throttling CVE-2024-47554 — apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader

🔗 References (33)