PT-2019-6216 · Apache · Apache Kafka

Published

2019-07-10

·

Updated

2022-05-24

·

CVE-2018-17196

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Kafka versions 0.11.0.0 through 2.1.0
Description The issue is related to insufficient access control in Apache Kafka when using Access Control Lists (ACLs). It allows an attacker to bypass security restrictions by crafting a special request. Only authenticated clients with Write permission on the respective topics can exploit this issue.
Recommendations For Apache Kafka versions 0.11.0.0 through 2.1.0, upgrade to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting Write permission on topics to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03778
CVE-2018-17196
GHSA-47W3-66WQ-CPXG

Affected Products

Apache Kafka