QID 375930
Date Published: 2021-10-05
QID 375930: Apache Kafka Timing Attack Vulnerability
Apache Kafka is an open-source distributed event streaming platform used for high-performance data pipelines, streaming analytics, data integration, and mission-critical applications.
Affected Versions:
Apache Kafka versions 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 2.8.0
QID Detection Logic:
The qid detects install location of Kafka through running processes and checks for the installed version.
Successful exploitation of this vulnerability may allow privilege escalation.
Solution
The Vendor has released security update to fix the vulnerability. For more information please visit Apache Kafka Downloads page.
Vendor References
- APACHE KAFKA SECURITY VULNERABILITIES -
kafka.apache.org/cve-list
CVEs related to QID 375930
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|