PT-2019-6216 · Apache · Apache Kafka

Publicado

2019-07-10

·

Atualizado

2022-05-24

·

CVE-2018-17196

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Kafka versions 0.11.0.0 through 2.1.0
Description The issue is related to insufficient access control in Apache Kafka when using Access Control Lists (ACLs). It allows an attacker to bypass security restrictions by crafting a special request. Only authenticated clients with Write permission on the respective topics can exploit this issue.
Recommendations For Apache Kafka versions 0.11.0.0 through 2.1.0, upgrade to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting Write permission on topics to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03778
CVE-2018-17196
GHSA-47W3-66WQ-CPXG

Produtos afetados

Apache Kafka