Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47w3-66wq-cpxg

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Input Validation in Apache Kafka

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

Пакеты

Наименование

org.apache.kafka:kafka

maven
Затронутые версииВерсия исправления

>= 0.11.0.0, <= 2.1.0

2.1.1

EPSS

Процентиль: 92%
0.05479
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
redhat
около 7 лет назад

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

CVSS3: 8.8
nvd
около 7 лет назад

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

CVSS3: 8.8
debian
около 7 лет назад

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to ...

CVSS3: 8.8
fstec
около 7 лет назад

Уязвимость диспетчера сообщений Apache Kafka, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 92%
0.05479
Низкий

8.8 High

CVSS3

Дефекты

CWE-20