Apache

Kafka

13 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 10.06.2025 07:55:14
  • Last modified 11.07.2025 16:58:15

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint....

  • EPSS 0.49%
  • Published 10.06.2025 07:54:41
  • Last modified 11.07.2025 16:52:33

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To ...

  • EPSS 0.23%
  • Published 10.06.2025 07:52:31
  • Last modified 11.07.2025 16:54:35

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS ...

  • EPSS 0.3%
  • Published 18.12.2024 14:15:23
  • Last modified 20.06.2025 18:13:13

Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of R...

  • EPSS 0.21%
  • Published 19.11.2024 09:15:03
  • Last modified 15.07.2025 16:42:34

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipu...

  • EPSS 0.29%
  • Published 12.04.2024 07:15:08
  • Last modified 10.06.2025 00:59:50

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource asso...

  • EPSS 0.05%
  • Published 20.09.2022 09:15:09
  • Last modified 29.05.2025 14:15:28

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemory...

  • EPSS 0.95%
  • Published 22.09.2021 09:15:07
  • Last modified 21.11.2024 06:16:30

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0....

  • EPSS 0.6%
  • Published 28.11.2020 01:15:11
  • Last modified 21.11.2024 05:20:52

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if a...

  • EPSS 3.16%
  • Published 14.01.2020 15:15:12
  • Last modified 21.11.2024 04:22:45

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring...