CVE-2023-25194
Apache Kafka Connect: JNDI attack through a JndiLoginModule SASL JAAS configuration
Technology
Apache Kafka
CVSS Score
8.8 / 10.0
Affected Versions
Kafka Connect 2.3.0 to 3.3.2
Upstream Fix
3.4.0
Published
February 7, 2023
OSSeva Coverage
Fixed upstream
Description
An operator who can create or modify connectors through the Kafka Connect REST API can set sasl.jaas.config for a connector's Kafka clients to com.sun.security.auth.module.JndiLoginModule, through the producer, consumer or admin override properties. The worker then connects to an LDAP server of the attacker's choice and deserializes the response, which can lead to denial of service or remote code execution when gadgets are on the classpath. Kafka 3.4.0 added the org.apache.kafka.disallowed.login.modules system property and disables JndiLoginModule by default.
Is your Apache Kafka deployment affected?
If you're running Kafka Connect 2.3.0 to 3.3.2, you need this patch. Book a discovery call to get covered.