Back to Vulnerability Directory
HIGHFixed upstream

CVE-2018-17196

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce…

Technology

Apache Kafka

CVSS Score

8.8 / 10.0

Affected Versions

>=0.11.0.0 <=2.1.0

Upstream Fix

See upstream advisory

Published

July 11, 2019

OSSeva Coverage

Fixed upstream

Description

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

Is your Apache Kafka deployment affected?

If you're running >=0.11.0.0 <=2.1.0, you need this patch. Book a discovery call to get covered.