Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2xx-f8r3-9mg5

Опубликовано: 17 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

STRIMZI incorrect access control

Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists), and potentially steal Kafka SASL credentials, by querying the MirrorMaker Kafka REST API.

Пакеты

Наименование

io.strimzi:strimzi

maven
Затронутые версииВерсия исправления

<= 0.41.0

Отсутствует

EPSS

Процентиль: 32%
0.00124
Низкий

7.3 High

CVSS3

Дефекты

CWE-306
CWE-400

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists), and potentially steal Kafka SASL credentials, by querying the MirrorMaker Kafka REST API.

EPSS

Процентиль: 32%
0.00124
Низкий

7.3 High

CVSS3

Дефекты

CWE-306
CWE-400