First published: Wed Mar 05 2025(Updated: )
Red Hat Streams for Apache Kafka, based on the Apache Kafka project, offers a distributed<br>backbone that allows microservices and other applications to share data with<br>extremely high throughput and extremely low latency.<br>This release of Red Hat Streams for Apache Kafka 2.9.0 serves as a replacement for Red Hat Streams for Apache Kafka 2.8.0, and includes security and bug fixes, and enhancements.<br>Security Fix(es):<br><li> Cruise Control:cio.netty:netty-common:4.1.115.Final-redhat [amq-st-2] "(CVE-2023-52428)"</li> <li> Cruise Control:com.nimbusds:nimbus-jose-jwt:9.37.2.redhat [amq-st-2] "(CVE-2024-47535)"</li> <li> Cruise Control:org.apache.kafka:kafka-clients:3.5.2.redhat+ [amq-st-2] "(CVE-2024-31141)"</li> <li> Cruise Control:io:commons-io:2.15.1.redhat+ [amq-st-2] "(CVE-2024-47554)"</li> <li> Cruise Control:org.eclipse.jetty:jetty-server:9.4.56.v20240826-redhat+ [amq-st-2] "(CVE-2024-8184)"</li> <li> Cruise Control:org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks [amq-st-2] "(CVE-2024-8184)"</li> <li> Kafka Exporter:golang-github-danielqsj-kafka_exporter: Golang FIPS zeroed buffer [amq-st-2] "(CVE-2024-9355)"</li> <li> Kafka Exporter:golang-github-danielqsj-kafka_exporter: net/<a href="http:" target="_blank">http:</a> Denial of service due to improper 100-continue handling in net/http [amq-st-2] "(CVE-2024-24791)"</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Kafka |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:2416 is critical due to its impact on the security of Red Hat Streams for Apache Kafka.
To fix RHSA-2025:2416, upgrade Red Hat Streams for Apache Kafka to version 2.9.0 or later.
RHSA-2025:2416 affects Red Hat Streams for Apache Kafka versions up to and including 2.8.0.
Yes, RHSA-2025:2416 is related to Apache Kafka as it is based on the Apache Kafka project.
Red Hat Streams for Apache Kafka provides a distributed backbone for microservices with high throughput and low latency for data sharing.