Session hijacking in Apache Kafka - CVE-2017-12610
Published: July 30, 2018 / Updated: July 31, 2018
Apache Kafka
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to conduct an impersonation attack on the target system.
The vulnerability exists in the built-in PLAIN or Salted Challenge Response Authentication Mechanism (SCRAM) server implementations due to improper processing of protocol messages when the affected software uses Simple Authentication and Security Layer (SASL)/PLAIN or SASL/SCRAM authentication. A remote unauthenticated attacker can send a malicious protocol message and impersonate other users, which could be used to conduct further attacks.