PT-2026-20655 · Unknown+2 · Kubernetes+3
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Strimzi versions 0.49.0 through 0.50.0
Description
Strimzi allows running an Apache Kafka cluster on Kubernetes or OpenShift. Versions 0.49.0 through 0.50.0 incorrectly configure trusted certificates for mTLS authentication when using a custom Cluster or Clients CA with a multistage CA chain. This allows users with certificates signed by any CA in the chain to authenticate. The issue only affects users utilizing a custom Cluster or Clients CA with a multistage CA chain and does not impact those using Strimzi-managed CAs or a single custom CA.
Recommendations
Versions 0.49.0 through 0.50.0: Upgrade to version 0.50.1 or later.
Versions 0.49.0 through 0.50.0: Provide only the single CA that should be used instead of the full CA chain as the custom CA.
Exploit
Fix
Improper Certificate Validation
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kafka
Kubernetes
Openshift
Strimzi