Skip to content

Conversation

davidzollo
Copy link
Contributor

Upgrade Apache Kafka (CVE-2023-25194) and PostgreSQL JDBC (CVE-2024-1597) to fix critical security vulnerabilities

  • Apache Kafka was upgraded to mitigate a JNDI injection vulnerability (CVE-2023-25194). This vulnerability could allow remote code execution when the Kafka client connects to a vulnerable Kafka instance. The upgrade to version 3.4.0 resolves this issue and strengthens security.

  • PostgreSQL JDBC driver has been upgraded to address SQL injection risks due to improper handling of 'PreferQueryMode=simple' (CVE-2024-1597). The upgrade prevents unauthorized SQL execution, improving overall database security.

  • SQLServer version is to solve oom of TDS protocol

@github-actions github-actions bot added core SeaTunnel core module connectors-v2 format labels Sep 8, 2025
@davidzollo davidzollo force-pushed the dev-fix-cve-issues-pg-kafka branch from 54da44d to d8cb20a Compare September 8, 2025 15:13
@davidzollo davidzollo force-pushed the dev-fix-cve-issues-pg-kafka branch from d8cb20a to b572e2f Compare September 8, 2025 15:29
@davidzollo davidzollo marked this pull request as draft September 12, 2025 03:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
connectors-v2 core SeaTunnel core module format
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant