From fe927e65aac7f74f38e33da6749ddb99b7e0fb5c Mon Sep 17 00:00:00 2001 From: Paul-Christian Volkmer Date: Fri, 29 Dec 2023 17:06:47 +0100 Subject: [PATCH] chore: remove explicit kafka dependency version Spring Boot 3.6.1 uses Kafka 3.6.1 that mitigates CVE-2023-34453, CVE-2023-34454, CVE-2023-34455, CVE-2023-43642 and new CVE-2023-44981 from version 3.6.0 --- build.gradle.kts | 4 ---- 1 file changed, 4 deletions(-) diff --git a/build.gradle.kts b/build.gradle.kts index 851bcaa..3a5e9fe 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -20,10 +20,6 @@ var versions = mapOf( "mockito-kotlin" to "5.1.0" ) -// Override Apache Kafka to be used -// Fixes: CVE-2023-34455, CVE-2023-34454, CVE-2023-34453 and CVE-2023-43642 -extra["kafka.version"] = "3.6.0" - java { sourceCompatibility = JavaVersion.VERSION_17 }