PT-2026-48327 · Vmware · Spring For Apache Kafka
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spring for Apache Kafka versions 4.0.0 through 4.0.5
Spring for Apache Kafka versions 3.3.0 through 3.3.15
Spring for Apache Kafka versions 3.2.0 through 3.2.13
Spring for Apache Kafka versions 2.9.0 through 2.9.13
Spring for Apache Kafka versions 2.8.0 through 2.8.11
Description
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper use a prefix check to match type headers against trusted packages. This mechanism causes any trusted package to implicitly trust all of its subpackages. When combined with Jackson's default bean deserialization, a producer can provide crafted header values that lead the consumer to deserialize arbitrary JDK types.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring For Apache Kafka