Last modified by Erik Bakker on 2022/06/16 13:50

From version 12.1
edited by Erik Bakker
on 2022/06/16 13:36
Change comment: There is no comment for this version
To version 10.1
edited by Erik Bakker
on 2022/06/16 13:31
Change comment: There is no comment for this version

Summary

Details

Page properties
Title
... ... @@ -1,1 +1,1 @@
1 -eMagiz Kafka Connector - 1.1.1
1 +eMagiz Runtime - 5.0.4
Content
... ... @@ -1,8 +1,12 @@
1 -The 1.1.1 version of the eMagiz Kafka connector (EMKC) fixes one issue related to the consumer commits.
1 +Fourth maintenance release in the eMagiz 5.0.x line. This release fixes Log4J security vulnerabilities CVE-2021-44228 and CVE-2021-45046.
2 2  
3 +Find out more in our [release blog]
3 3  
5 +
4 4  ===== Bug Fixes =====
5 5  
6 -* Corrected the position when a consumer commits its offset, preventing loss of data.
8 +* Updated OPS4J Pax Logging version 1.10.1 to version 1.11.11. Internally this uses Apache Log4j 2, which is updated from version 2.8.2 to 2.16.0 in this release. This fixed the following two security vulnerabilities:
9 + ** https://nvd.nist.gov/vuln/detail/CVE-2021-44228 (CVSS score 10.0 - Critical)
10 + ** https://nvd.nist.gov/vuln/detail/CVE-2021-45046 (CVSS score 3.7 - Low)
7 7  
8 8