PT-2025-49308 · Strimzi+3 · Strimzi+5
Published
2025-12-05
·
Updated
2026-03-04
·
CVE-2025-66623
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Strimzi versions 0.47.0 through 0.49.0
Description
Strimzi allows running an Apache Kafka cluster on Kubernetes or OpenShift. Versions from 0.47.0 up to 0.49.0 incorrectly create a Kubernetes Role. This role grants Apache Kafka Connect and Apache Kafka MirrorMaker 2 operands GET access to all Kubernetes Secrets within a given Kubernetes namespace.
Recommendations
Update to Strimzi version 0.49.1 or later.
Exploit
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kafka
Apache Kafka Connect
Apache Kafka Mirrormaker 2
Kubernetes
Openshift
Strimzi