QID 375930

Date Published: 2021-10-05

QID 375930: Apache Kafka Timing Attack Vulnerability

Apache Kafka is an open-source distributed event streaming platform used for high-performance data pipelines, streaming analytics, data integration, and mission-critical applications.

Affected Versions:
Apache Kafka versions 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, 2.8.0

QID Detection Logic:
The qid detects install location of Kafka through running processes and checks for the installed version.

Successful exploitation of this vulnerability may allow privilege escalation.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The Vendor has released security update to fix the vulnerability. For more information please visit Apache Kafka Downloads page.
    Vendor References

    CVEs related to QID 375930

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo kafka.apache.org/cve-list