Apache KafkaGHSA-xm78-4m3g-7wm7
Improper Authentication in Apache Kafka
Medium6.8CVE-2017-12610 · Published May 13, 2022 · updated Nov 8, 2023
In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kafka:kafka-clients Maven | >= 0.10.0.0, < 0.10.2.2 | 0.10.2.2 |
| >= 0.11.0.0, < 0.11.0.2 | 0.11.0.2 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2017-12610
- nvd.nist.gov/vuln/detail/CVE-2017-12610
- lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- lists.apache.org/thread.html/b6157be1a09df332294213bd21e90dcf9fe4c1810193be54620e4210@%3Cusers.kafka.apache.org%3E
- lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- www.oracle.com/security-alerts/cpujul2020.html
- www.securityfocus.com/bid/104899
More Apache Kafka advisories
All Apache Kafka| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 102025 | Apache Kafka Deserialization of Untrusted Data vulnerability | High8.8 | 3.4.0 |
| Jun 102025 | Apache Kafka Deserialization of Untrusted Data vulnerability | High8.8 | 3.9.1 |
| Jun 102025 | Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability | Medium7.5 | 3.9.1 |
| Dec 182024 | Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm | Low5.3 | 3.7.2+1 more |
| Nov 192024 | Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider | Medium6.5 | 3.7.1 |
| Sep 232021 | Observable Discrepancy in Apache Kafka | Medium5.9 | 2.6.3+2 more |