CVE-2017-12610

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
26/07/2018
Last modified:
07/11/2023

Description

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* 0.10.0.0 (including) 0.10.2.1 (including)
cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* 0.11.0.0 (including) 0.11.0.1 (including)