Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47w3-66wq-cpxg

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Input Validation in Apache Kafka

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

Пакеты

Наименование

org.apache.kafka:kafka

maven
Затронутые версииВерсия исправления

>= 0.11.0.0, <= 2.1.0

2.1.1

EPSS

Процентиль: 59%
0.00381
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
redhat
больше 6 лет назад

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

CVSS3: 8.8
nvd
больше 6 лет назад

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

CVSS3: 8.8
debian
больше 6 лет назад

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to ...

CVSS3: 8.8
fstec
больше 6 лет назад

Уязвимость диспетчера сообщений Apache Kafka, связанная с недостатками разграничения доступа, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 59%
0.00381
Низкий

8.8 High

CVSS3

Дефекты

CWE-20