CVE-2023-52251

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
25/01/2024
Last modified:
17/06/2025

Description

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:provectus:ui:*:*:*:*:*:kafka:*:* 0.4.0 (including) 0.7.1 (including)