HIGH🇵🇱 Wersja polska

CVE-2025-27819

CVSS 7.5v3.1pub. 2025-06-10upd. 2025-07-11

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource. Since Apache Kafka 3.4.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule" is disabled in Apache Kafka 3.4.0, and "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" is disabled by default in in Apache Kafka 3.9.1/4.0.0

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Apache Kafka

    APP
    Apache
    2.0.0 – 3.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSDeserialization
CWE
References

Related vulnerabilities

CVE-2026-33557CRITICAL9.1PL ✓same product

Apache Kafka: brak walidacji podpisu JWT w domyślnej konfiguracji SASL/OAUTHBEARER

CVE-2026-35554HIGH8.7same product

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be si...

CVE-2025-27817HIGH7.5same product

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka...

CVE-2025-27818HIGH8.8same product

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig t...

CVE-2024-27309HIGH7.4same product

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not...