Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-31141

Apache Kafka Clients: ConfigProviders let untrusted configuration read files and environment variables

Technology

Apache Kafka

CVSS Score

6.5 / 10.0

Affected Versions

Kafka Clients 2.3.0 to 3.7.0

Upstream Fix

3.7.1; 3.8.0

Published

November 19, 2024

OSSeva Coverage

Fixed upstream

Description

Kafka Clients ship FileConfigProvider, DirectoryConfigProvider and EnvVarConfigProvider, which can read from disk or from environment variables. Where an untrusted party can supply client configuration, these providers can be used to read arbitrary files and environment variables, for example to escalate from Kafka Connect REST API access to file system access. Fixed in 3.7.1 and 3.8.0; Kafka advises setting the org.apache.kafka.automatic.config.providers=none system property in affected applications.

Upstream record: NVD · CVE.org

Is your Apache Kafka deployment affected?

If you're running Kafka Clients 2.3.0 to 3.7.0, you need this patch. Book a discovery call to get covered.