Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-56128
Apache Kafka: SCRAM authentication can be replayed when used without encryption
Technology
Apache Kafka
CVSS Score
5.3 / 10.0
Affected Versions
0.10.2.0 to 3.7.1; 3.8.0
Upstream Fix
3.7.2; 3.8.1; 3.9.0
Published
December 18, 2024
OSSeva Coverage
Fixed upstream
Description
Kafka's SCRAM implementation did not check, as RFC 5802 requires, that the nonce in the client's second message matches the nonce the server sent in its first message. An attacker with plaintext access to a SCRAM exchange could replay it. Deployments that run SCRAM over TLS are not affected. Fixed in 3.7.2, 3.8.1 and 3.9.0.
Is your Apache Kafka deployment affected?
If you're running 0.10.2.0 to 3.7.1; 3.8.0, you need this patch. Book a discovery call to get covered.