Input validation error in Apache Kafka - #VU21213
Published: September 19, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated attacker with permission to create topics can unexpectedly terminate a cluster of Kafka server processes with the specially crafted topic names.
Affected software
TIBCO Messaging - Apache Kafka Distribution - Core - Enterprise Edition
TIBCO Messaging - Apache Kafka Distribution - Core - Community Edition
Remediation
TIBCO Messaging - Apache Kafka Distribution - Core - Enterprise Edition - update to 2.2.0-1
TIBCO Messaging - Apache Kafka Distribution - Core - Community Edition - update to 2.2.0-1