PT-2025-49308 · Apache+3 · Apache Kafka Connect+5
CVE-2025-66623
·
Published
2025-12-05
·
Updated
2026-03-04
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Strimzi versions 0.47.0 through 0.49.0
Description
Strimzi allows running an Apache Kafka cluster on Kubernetes or OpenShift. Versions from 0.47.0 up to 0.49.0 incorrectly create a Kubernetes Role. This role grants Apache Kafka Connect and Apache Kafka MirrorMaker 2 operands GET access to all Kubernetes Secrets within a given Kubernetes namespace.
Recommendations
Update to Strimzi version 0.49.1 or later.
Exploit
Fix
Information Disclosure
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kafka
Apache Kafka Connect
Apache Kafka Mirrormaker 2
Kubernetes
Openshift
Strimzi