In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.
2018-07-26T14:29:00.327
2024-11-21T03:09:53.320
Modified
CVSSv3.0: 6.8 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:N
6.8
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | kafka | ≤ 0.10.2.1 | Yes |
Application | apache | kafka | ≤ 0.11.0.1 | Yes |