VYPR

Maven package

io.strimzi/strimzi

pkg:maven/io.strimzi/strimzi

Vulnerabilities (2)

  • CVE-2025-66623Dec 5, 2025
    affected >= 0.47.0, < 0.49.1fixed 0.49.1

    Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apache Kafka Connect and Apache Kafka MirrorMa

  • CVE-2024-36543CriJun 17, 2024
    affected <= 0.41.0

    Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists), a