Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c8p-h27x-rrc9

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 5.4
nvd
1 день назад

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-693