A zero-day vulnerability (CVE-2022-22965) dubbed Spring4shell has been disclosed yesterday in the Java framework SpringBoot that is used in some StreamSets software.
StreamSets team would like to inform you that we have verified that all our products and components are not using the specific combination and configuration of the vulnerable components and therefore we conclude that StreamSets software is not vulnerable.
We are continuously monitoring the situation as the situation evolves and we will inform you if any important news comes to the light.