Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12399

Опубликовано: 14 янв. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7kafka-clientsNot affected
Red Hat Fuse 7kafkaNot affected
Red Hat JBoss Fuse 6kafkaNot affected
Red Hat OpenShift Application RuntimeskafkaNot affected
Red Hat OpenShift Application Runtimeskafka-clientsNot affected
Red Hat Process Automation 7kafka-clientsNot affected
Red Hat AMQ Streams 1kafkaFixedRHSA-2020:093923.03.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1796593kafka: Connect REST API exposes plaintext secrets in tasks endpoint

EPSS

Процентиль: 84%
0.02307
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.

CVSS3: 7.5
debian
около 6 лет назад

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0 ...

CVSS3: 7.5
github
больше 5 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Kafka

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость компонента Connect workers диспетчера сообщений Apache Kafka, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 84%
0.02307
Низкий

7.5 High

CVSS3