Описание
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
A flaw was found in confluent-kafka. The HashiCorp Vault Key Management Service (KMS) integration fails to properly validate Transport Layer Security (TLS) certificates by default. A remote attacker able to intercept network traffic could exploit this flaw to intercept and decrypt sensitive data or tamper with communications between the client and the Vault service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | satellite/iop-advisor-backend-rhel9 | Affected | ||
| Red Hat Satellite 6 | satellite/iop-host-inventory-rhel9 | Affected | ||
| Red Hat Satellite 6 | satellite/iop-insights-engine-rhel9 | Affected | ||
| Red Hat Satellite 6 | satellite/iop-puptoo-rhel9 | Affected | ||
| Red Hat Satellite 6 | satellite/iop-yuptoo-rhel9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
EPSS
7.4 High
CVSS3