PT-2025-24331 · Apache+1 · Apache Kafka+1
Trganda
·
Published
2025-01-13
·
Updated
2025-08-20
·
CVE-2025-49127
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kafbat UI version 1.0.0
Kafbat UI versions prior to 1.1.0
Description
Kafbat UI is a web user interface designed for managing Apache Kafka clusters. An unsafe deserialization vulnerability exists that allows any unauthenticated user to execute arbitrary code on the server. The issue stems from the application’s dynamic cluster configuration functionality that accepts user-provided JMX endpoints without proper validation.
Recommendations
Kafbat UI version 1.0.0: Upgrade to version 1.1.0 or later to resolve this issue.
Kafbat UI versions prior to 1.1.0: Upgrade to version 1.1.0 or later to resolve this issue.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Kafka
Kafbat Ui