Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-25194

Apache Kafka Connect: JNDI attack through a JndiLoginModule SASL JAAS configuration

Technology

Apache Kafka

CVSS Score

8.8 / 10.0

Affected Versions

Kafka Connect 2.3.0 to 3.3.2

Upstream Fix

3.4.0

Published

February 7, 2023

OSSeva Coverage

Fixed upstream

Description

An operator who can create or modify connectors through the Kafka Connect REST API can set sasl.jaas.config for a connector's Kafka clients to com.sun.security.auth.module.JndiLoginModule, through the producer, consumer or admin override properties. The worker then connects to an LDAP server of the attacker's choice and deserializes the response, which can lead to denial of service or remote code execution when gadgets are on the classpath. Kafka 3.4.0 added the org.apache.kafka.disallowed.login.modules system property and disables JndiLoginModule by default.

Upstream record: NVD · CVE.org

Is your Apache Kafka deployment affected?

If you're running Kafka Connect 2.3.0 to 3.3.2, you need this patch. Book a discovery call to get covered.