CVE-2024-31141
Apache Kafka Clients: ConfigProviders let untrusted configuration read files and environment variables
Technology
Apache Kafka
CVSS Score
6.5 / 10.0
Affected Versions
Kafka Clients 2.3.0 to 3.7.0
Upstream Fix
3.7.1; 3.8.0
Published
November 19, 2024
OSSeva Coverage
Fixed upstream
Description
Kafka Clients ship FileConfigProvider, DirectoryConfigProvider and EnvVarConfigProvider, which can read from disk or from environment variables. Where an untrusted party can supply client configuration, these providers can be used to read arbitrary files and environment variables, for example to escalate from Kafka Connect REST API access to file system access. Fixed in 3.7.1 and 3.8.0; Kafka advises setting the org.apache.kafka.automatic.config.providers=none system property in affected applications.
Is your Apache Kafka deployment affected?
If you're running Kafka Clients 2.3.0 to 3.7.0, you need this patch. Book a discovery call to get covered.