578
VMScore

CVE-2018-17196

Published: 11/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache kafka

Vendor Advisories

Impact: Important Public Date: 2019-07-11 CWE: CWE-20 Bugzilla: 1732309: CVE-2018-17196 kafka: potentia ...

Github Repositories

Repository for the sudo group.

Apache Kafka Description and Statistics Kafka is a distributed streaming platform that functions as a messaging system, storage system, and as a stream processor For messaging, Kafka can do both scale processing and multi-subscriber at the same time For Kafka as a storage system, Kafka stores and replicates all data to disks for redundancy and allows for the users to request