Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-30677

Apache Pulsar IO Kafka connectors log Kafka credentials in plain text

Technology

Apache Pulsar

CVSS Score

6.5 / 10.0

Affected Versions

all versions before 3.0.11, 3.3.6 and 4.0.4

Upstream Fix

3.0.11; 3.3.6; 4.0.4

Published

April 9, 2025

OSSeva Coverage

Fixed upstream

Description

The Pulsar IO Apache Kafka source and sink connectors and the Kafka Connect adaptor sink log sensitive configuration properties, including Kafka credentials, in plain text. An attacker needs access to the application logs.

Upstream record: NVD · CVE.org

Is your Apache Pulsar deployment affected?

If you're running all versions before 3.0.11, 3.3.6 and 4.0.4, you need this patch. Book a discovery call to get covered.