PT-2024-27064 · Unknown · Strimzi Project

Published

2024-06-17

·

Updated

2024-07-03

·

CVE-2024-36543

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions STRIMZI Project versions 0.41.0 and earlier
Description The issue is related to incorrect access control in the Kafka Connect REST API, which can be exploited to deny service for Kafka Mirroring. An attacker can potentially mirror topics' content to their own Kafka cluster via a malicious connector, bypassing existing Kafka ACL if it exists. Additionally, there is a risk of stealing Kafka SASL credentials by querying the MirrorMaker Kafka REST API.
Recommendations For STRIMZI Project versions 0.41.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-36543
GHSA-Q2XX-F8R3-9MG5

Affected Products

Strimzi Project