Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZqbWYtbXh3Zi1yM2pj

Exposure of Sensitive Information to an Unauthorized Actor in Apache Kafka

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.

Permalink: https://github.com/advisories/GHSA-6jmf-mxwf-r3jc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZqbWYtbXh3Zi1yM2pj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 4 years ago
Updated: about 1 year ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-6jmf-mxwf-r3jc, CVE-2019-12399
References: Blast Radius: 1.0

Affected Packages

maven:org.apache.kafka:kafka
Affected Version Ranges: = 2.3.0, >= 2.2.0, <= 2.2.1, >= 2.1.0, <= 2.1.1, >= 2.0.0, <= 2.0.1
Fixed in: 2.3.1, 2.2.2, 2.1.2, 2.0.2