Skip to content
Apache KafkaGHSA-xm78-4m3g-7wm7

Improper Authentication in Apache Kafka

Medium6.8CVE-2017-12610 · Published May 13, 2022 · updated Nov 8, 2023

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kafka:kafka-clients
Maven
>= 0.10.0.0, < 0.10.2.20.10.2.2
>= 0.11.0.0, < 0.11.0.20.11.0.2
Details and references

More Apache Kafka advisories

All Apache Kafka
Advisory
Apache Kafka Deserialization of Untrusted Data vulnerability
High8.8Jun 10, 2025
Apache Kafka Deserialization of Untrusted Data vulnerability
High8.8Jun 10, 2025
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
Medium7.5Jun 10, 2025
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
Low5.3Dec 18, 2024
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
Medium6.5Nov 19, 2024
Observable Discrepancy in Apache Kafka
Medium5.9Sep 23, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.