Skip to content

Conversation

@bol444
Copy link
Collaborator

@bol444 bol444 commented Dec 4, 2025

What is the purpose of this change?

add lz4-java dependency to address CVE-2025-12183

lz4-java is a transitive dependency of kafka-clients

  • This vulnerability would
    • Enables DoS via service crashes
    • Enables information disclosure via adjacent memory read (potential credential leakage)
    • Affects Kafka message processing
  • Attack Prerequisites: Low complexity, no authentication required, remotely exploitable
  • kafka-clients Upgrade NOT Viable: All versions (3.9.1 to 4.1.1) still use vulnerable lz4-java:1.8.0

How was this change implemented?

pom update

How was this change tested?

ITs

Is there anything the reviewers should focus on/be aware of?

no

@bol444 bol444 marked this pull request as ready for review December 4, 2025 21:20
@bol444 bol444 requested a review from moodiRealist December 4, 2025 21:20
@sonarqube-solacecloud
Copy link

@bol444
Copy link
Collaborator Author

bol444 commented Dec 5, 2025

excluding this vulnerability instead, closing this PR, details are included in the ticket: https://sol-jira.atlassian.net/browse/DATAGO-118800

@bol444 bol444 closed this Dec 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant