PT-2023-22697 · Redpanda · Redpanda

Publicado

2023-04-08

·

Atualizado

2023-04-17

·

CVE-2023-30450

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Redpanda versions prior to 23.1.2 Redpanda versions 22.2 and 22.3 (before the backported fix)
Description The issue arises from the mishandling of the redpanda.rpc server tls field by rpk in Redpanda, leading to situations where there is a data type mismatch. This mismatch cannot be automatically fixed by rpk, and instead, a user must reconfigure (while a cluster is turned off) to have TLS on broker RPC ports.
Recommendations For Redpanda versions prior to 23.1.2, update to version 23.1.2 or later to resolve the issue. For Redpanda versions 22.2 and 22.3, apply the backported fix to resolve the issue. As a temporary workaround, consider reconfiguring the redpanda.rpc server tls field while the cluster is turned off to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30450

Produtos afetados

Redpanda