In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource. Since Apache Kafka 3.4.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule" is disabled in Apache Kafka 3.4.0, and "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" is disabled by default in in Apache Kafka 3.9.1/4.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HApache Kafka
APPApache2.0.0 – 3.3.2
Related vulnerabilities
Apache Kafka: brak walidacji podpisu JWT w domyślnej konfiguracji SASL/OAUTHBEARER
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be si...
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka...
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig t...
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not...