PT-2025-49308 · Strimzi+3 · Strimzi+5

Published

2025-12-05

·

Updated

2026-03-04

·

CVE-2025-66623

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Strimzi versions 0.47.0 through 0.49.0
Description Strimzi allows running an Apache Kafka cluster on Kubernetes or OpenShift. Versions from 0.47.0 up to 0.49.0 incorrectly create a Kubernetes Role. This role grants Apache Kafka Connect and Apache Kafka MirrorMaker 2 operands GET access to all Kubernetes Secrets within a given Kubernetes namespace.
Recommendations Update to Strimzi version 0.49.1 or later.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-66623
GHSA-XRHH-HX36-485Q

Affected Products

Apache Kafka
Apache Kafka Connect
Apache Kafka Mirrormaker 2
Kubernetes
Openshift
Strimzi