Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-27818

possible security vulnerability has been identified in Apache Kafka.

Technology

Apache Kafka

CVSS Score

8.8 / 10.0

Affected Versions

>=2.3.0 <3.9.1

Upstream Fix

See upstream advisory

Published

June 10, 2025

OSSeva Coverage

Fixed upstream

Description

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka clusters since Apache Kafka 2.0.0 (Kafka Connect 2.3.0). When configuring the broker via config file or AlterConfig command, or connector via the Kafka Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config` property for any of the connector's Kafka clients to "com.sun.security.auth.module.LdapLog

Is your Apache Kafka deployment affected?

If you're running >=2.3.0 <3.9.1, you need this patch. Book a discovery call to get covered.