PT-2019-6216 · Apache · Apache Kafka
Publicado
2019-07-10
·
Atualizado
2022-05-24
·
CVE-2018-17196
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Kafka versions 0.11.0.0 through 2.1.0
Description
The issue is related to insufficient access control in Apache Kafka when using Access Control Lists (ACLs). It allows an attacker to bypass security restrictions by crafting a special request. Only authenticated clients with Write permission on the respective topics can exploit this issue.
Recommendations
For Apache Kafka versions 0.11.0.0 through 2.1.0, upgrade to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting Write permission on topics to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Kafka