PT-2026-20654 · Strimzi+3 · Strimzi+5

Scholzj

·

Publicado

2026-02-19

·

Atualizado

2026-02-25

·

CVE-2026-27133

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Strimzi versions 0.47.0 through 0.50.1
Description Strimzi allows running an Apache Kafka cluster on Kubernetes or OpenShift. When multiple Certificate Authority (CA) certificates are used in the trusted certificates configuration of a Kafka Connect operand or a Kafka MirrorMaker 2 operand’s target cluster, all certificates within the CA chain are individually trusted when connecting to the Apache Kafka cluster. This can lead to the affected operand accepting connections from Kafka brokers using server certificates signed by any CA in the chain, rather than only the final CA.
Recommendations Update to version 0.50.1 or later.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27133
GHSA-6X85-J2F7-4XC5

Produtos afetados

Apache Kafka
Kafka Connect
Kafka Mirrormaker 2
Kubernetes
Openshift
Strimzi