#VU19227 Improper access control in Apache Kafka - CVE-2018-1288
Published: July 17, 2019
Apache Kafka
Apache Foundation
Description
The vulnerability allows a remote authenticated attacker to bypass certain security restrictions.
The vulnerability exists due to absent access controls when executing actions reserved for the Broker. A remote authenticated attacker can manually create fetch requests and interfere with data replication process that can lead to data loss.