MEDIUM · 5.9

CVE-2021-38153

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful...

Vulnerability Description

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ApacheKafka>= 2.0.0, < 2.6.3
QuarkusQuarkus< 2.2.4
OracleCommunications Brm - Elastic Charging Engine< 12.0.0.4.6
OracleCommunications Cloud Native Core Policy1.15.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6.0, <= 8.0.9.0
OracleFinancial Services Behavior Detection Platform>= 8.0.6.0.0, <= 8.0.8.0
OracleFinancial Services Enterprise Case Management8.0.7.1
OraclePrimavera Unifier18.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-38153?

CVE-2021-38153 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful...

How severe is CVE-2021-38153?

CVE-2021-38153 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-38153?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Kafka, Quarkus Quarkus, Oracle Communications Brm - Elastic Charging Engine, Oracle Communications Cloud Native Core Policy, Oracle Financial Services Analytical Applications Infrastructure.