CVE-2025-27817
- EPSS 0.03%
- Veröffentlicht 10.06.2025 07:55:14
- Zuletzt bearbeitet 11.07.2025 16:58:15
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint....
CVE-2025-27819
- EPSS 0.49%
- Veröffentlicht 10.06.2025 07:54:41
- Zuletzt bearbeitet 11.07.2025 16:52:33
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To ...
CVE-2025-27818
- EPSS 0.23%
- Veröffentlicht 10.06.2025 07:52:31
- Zuletzt bearbeitet 11.07.2025 16:54:35
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS ...
CVE-2024-56128
- EPSS 0.3%
- Veröffentlicht 18.12.2024 14:15:23
- Zuletzt bearbeitet 20.06.2025 18:13:13
Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of R...
CVE-2024-31141
- EPSS 0.21%
- Veröffentlicht 19.11.2024 09:15:03
- Zuletzt bearbeitet 15.07.2025 16:42:34
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipu...
CVE-2024-27309
- EPSS 0.29%
- Veröffentlicht 12.04.2024 07:15:08
- Zuletzt bearbeitet 10.06.2025 00:59:50
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource asso...
CVE-2022-34917
- EPSS 0.05%
- Veröffentlicht 20.09.2022 09:15:09
- Zuletzt bearbeitet 29.05.2025 14:15:28
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemory...
CVE-2021-38153
- EPSS 0.95%
- Veröffentlicht 22.09.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:30
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0....
CVE-2020-27218
- EPSS 0.6%
- Veröffentlicht 28.11.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:20:52
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if a...
CVE-2019-12399
- EPSS 3.16%
- Veröffentlicht 14.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:22:45
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring...