Skip to content

Fix plexus-utils cve#461

Open
srishti-saraswat wants to merge 1 commit intosplunk:developfrom
srishti-saraswat:CC-40234
Open

Fix plexus-utils cve#461
srishti-saraswat wants to merge 1 commit intosplunk:developfrom
srishti-saraswat:CC-40234

Conversation

@srishti-saraswat
Copy link
Copy Markdown

@srishti-saraswat srishti-saraswat commented Apr 10, 2026

Issue - CVE-2025-67030 | kafka-connect-splunk:2.2.5 | org.codehaus.plexus:plexus-utils:3.0.24

Fix - this comes in transitively from [jacoco-maven-plugin](https://mvnrepository.com/artifact/org.jacoco/jacoco-maven-plugin). However, there is no version of jacoco-maven-plugin with the fix of this cve, hence, pinning the fixed version for plexus-utils. We can remove the pinned version whenever there is a fixed version of jacoco-maven-plugin available.

[INFO] com.github.splunk.kafka.connect:splunk-kafka-connect:jar:v2.2.5
[INFO] \- org.codehaus.plexus:plexus-utils:jar:4.0.3:compile

@srishti-saraswat srishti-saraswat marked this pull request as ready for review April 10, 2026 10:44
@srishti-saraswat
Copy link
Copy Markdown
Author

Hi @pszkamruk-splunk , can you help review this?
Or assign it to appropriate reviewer? Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant