PT-2024-27064 · Unknown · Strimzi Project
Published
2024-06-17
·
Updated
2024-07-03
·
CVE-2024-36543
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
STRIMZI Project versions 0.41.0 and earlier
Description
The issue is related to incorrect access control in the Kafka Connect REST API, which can be exploited to deny service for Kafka Mirroring. An attacker can potentially mirror topics' content to their own Kafka cluster via a malicious connector, bypassing existing Kafka ACL if it exists. Additionally, there is a risk of stealing Kafka SASL credentials by querying the MirrorMaker Kafka REST API.
Recommendations
For STRIMZI Project versions 0.41.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Strimzi Project