Vulnerability Description
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Kafka | >= 0.11.0.0, <= 2.1.0 |
References
- http://www.securityfocus.com/bid/109139Third Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12e
- https://lists.apache.org/thread.html/d1581fb6464c9bec8a72575c01f5097d68e2fbb230a
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d28
- https://lists.apache.org/thread.html/r66de86b9a608c1da70b2d27d765c11ec88edf6e5dd
- https://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc2
- https://lists.apache.org/thread.html/rc27d424d0bdeaf31081c3e246db3c66e882243ae3f
- https://www.mail-archive.com/dev%40kafka.apache.org/msg99277.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- http://www.securityfocus.com/bid/109139Third Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12e
- https://lists.apache.org/thread.html/d1581fb6464c9bec8a72575c01f5097d68e2fbb230a
FAQ
What is CVE-2018-17196?
CVE-2018-17196 is a vulnerability with a CVSS score of 8.8 (HIGH). In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write perm...
How severe is CVE-2018-17196?
CVE-2018-17196 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17196?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Kafka.