#VU19218 Improper access control in Apache Kafka - CVE-2018-17196
Published: July 17, 2019
Apache Kafka
Apache Foundation
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper security restrictions imposed by the affected software. A remote authenticated attacker with write permission on respective topics can send a crafted Produce request that is designed to bypass transaction/idempotent access control list (ACL) validation.