Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-12399


When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.


Published

2020-01-14T15:15:12.803

Last Modified

2024-11-21T04:22:45.463

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache kafka 2.0.0 Yes
Application apache kafka 2.0.1 Yes
Application apache kafka 2.1.0 Yes
Application apache kafka 2.1.1 Yes
Application apache kafka 2.2.0 Yes
Application apache kafka 2.2.1 Yes
Application apache kafka 2.3.0 Yes
Application oracle banking_corporate_lending_process_management 14.1.0 Yes
Application oracle banking_corporate_lending_process_management 14.3.0 Yes
Application oracle banking_corporate_lending_process_management 14.4.0 Yes
Application oracle banking_credit_facilities_process_management 14.1.0 Yes
Application oracle banking_credit_facilities_process_management 14.3.0 Yes
Application oracle banking_credit_facilities_process_management 14.4.0 Yes
Application oracle banking_liquidity_management ≤ 14.4.0 Yes
Application oracle banking_payments 14.4.0 Yes
Application oracle banking_platform 2.7.0 Yes
Application oracle banking_supply_chain_finance ≤ 14.4.0 Yes
Application oracle banking_trade_finance_process_management 14.1.0 Yes
Application oracle banking_trade_finance_process_management 14.3.0 Yes
Application oracle banking_trade_finance_process_management 14.4.0 Yes
Application oracle banking_virtual_account_management 14.1.0 Yes
Application oracle banking_virtual_account_management 14.3.0 Yes
Application oracle banking_virtual_account_management 14.4.0 Yes
Application oracle blockchain_platform < 21.1.2 Yes
Application oracle communications_cloud_native_core_policy 1.9.0 Yes
Application oracle financial_services_analytical_applications_infrastructure ≤ 8.1.0 Yes
Application oracle flexcube_universal_banking 14.4.0 Yes

References