Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-56128

Apache Kafka: SCRAM authentication can be replayed when used without encryption

Technology

Apache Kafka

CVSS Score

5.3 / 10.0

Affected Versions

0.10.2.0 to 3.7.1; 3.8.0

Upstream Fix

3.7.2; 3.8.1; 3.9.0

Published

December 18, 2024

OSSeva Coverage

Fixed upstream

Description

Kafka's SCRAM implementation did not check, as RFC 5802 requires, that the nonce in the client's second message matches the nonce the server sent in its first message. An attacker with plaintext access to a SCRAM exchange could replay it. Deployments that run SCRAM over TLS are not affected. Fixed in 3.7.2, 3.8.1 and 3.9.0.

Upstream record: NVD · CVE.org

Is your Apache Kafka deployment affected?

If you're running 0.10.2.0 to 3.7.1; 3.8.0, you need this patch. Book a discovery call to get covered.