Regarding Vulnerabilities reported on Cassandra Connector 2.7.0 release jars

12 views
Skip to first unread message

Pavan Rajendra Patil (C)

unread,
Jul 16, 2025, 6:13:29 AMJul 16
to debezium
Hi Team
We have identified 2 high vulnerabilities for below mentioned jars can you give us idea when this can be fixed or timeline for it. We tried upgrading this to stable version but it is breaking the functionality.

  1. jetty-server-9.4.12.v20180830.jar
  2. snakeyaml-1.26.jar

Chris Cranford

unread,
Jul 16, 2025, 7:55:14 PMJul 16
to debe...@googlegroups.com
Hi -

Thanks for the feedback, but unfortunately Debezium 2.7 is no longer maintained.
If this continues to be an issue on Debezium 3.2, please feel free to open a Jira [1].

Thanks,
-cc

[1]: https://issues.redhat.com/projects/DBZ
--
You received this message because you are subscribed to the Google Groups "debezium" group.
To unsubscribe from this group and stop receiving emails from it, send an email to debezium+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/debezium/77359977-fa27-4da9-b95a-c007e89296abn%40googlegroups.com.

Reply all
Reply to author
Forward
0 new messages