PT-2024-27064 · Unknown · Strimzi Project

CVE-2024-36543

·

Published

2024-06-17

·

Updated

2024-07-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions STRIMZI Project versions 0.41.0 and earlier
Description The issue is related to incorrect access control in the Kafka Connect REST API, which can be exploited to deny service for Kafka Mirroring. An attacker can potentially mirror topics' content to their own Kafka cluster via a malicious connector, bypassing existing Kafka ACL if it exists. Additionally, there is a risk of stealing Kafka SASL credentials by querying the MirrorMaker Kafka REST API.
Recommendations For STRIMZI Project versions 0.41.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-36543
GHSA-Q2XX-F8R3-9MG5

Affected Products

Strimzi Project