PT-2019-6216 · Apache · Apache Kafka
Published
2019-07-10
·
Updated
2022-05-24
·
CVE-2018-17196
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Kafka versions 0.11.0.0 through 2.1.0
Description
The issue is related to insufficient access control in Apache Kafka when using Access Control Lists (ACLs). It allows an attacker to bypass security restrictions by crafting a special request. Only authenticated clients with Write permission on the respective topics can exploit this issue.
Recommendations
For Apache Kafka versions 0.11.0.0 through 2.1.0, upgrade to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting Write permission on topics to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kafka