Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump OpenSSL in confluent-kafka to 3.4.1 on Windows #19608

Open
wants to merge 4 commits into
base: 7.63.x
Choose a base branch
from

Conversation

nubtron
Copy link
Contributor

@nubtron nubtron commented Feb 13, 2025

Fixes CVE-2024-12797.
3.4.1 is not on vcpkg.io yet but it's accessible in the CLI.

PS C:\Users\Administrator\Downloads\vcpkg> .\vcpkg.exe search openssl
...
openssl                  3.4.1            OpenSSL is an open source project that provides a robust, commercial-grade...

Upgrading to from 3.3.2 directly to 3.4.1 because it seems like the vcpkg project is skipping 3.3.3 and upgrading the 3.4.X branch instead.
The CVE was already fixed on Linux and MacOS in a previous commit.

@nubtron nubtron requested review from a team as code owners February 13, 2025 13:34
@nubtron nubtron marked this pull request as draft February 13, 2025 14:19
@nubtron
Copy link
Contributor Author

nubtron commented Feb 13, 2025

Updated the commit for vcpkg so that it includes the OpenSSL fix. Also switched from using tags to commits. Vcpkg updates their tags monthly, and we probably don't want to wait that long to fix our CVEs.

@nubtron nubtron marked this pull request as ready for review February 13, 2025 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants