Information disclosure in Apache Kafka - CVE-2019-12399

 

Information disclosure in Apache Kafka - CVE-2019-12399

Published: January 14, 2020


Vulnerability identifier: #VU24240
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12399
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output within the Apache Kafka Connect REST API tasks endpoint. A remote authenticated user can issue a request to the same Connect cluster to obtain the connector's task configurations and the response will contain the plaintext secret.


Affected software

Apache Kafka
AMQ Streams
Oracle Communications Cloud Native Core Policy
IBM Security Guardium Insights
Oracle Blockchain Platform
Oracle Banking Platform
Oracle Financial Services Analytical Applications Infrastructure
Oracle FLEXCUBE Universal Banking
Oracle Banking Liquidity Management
Oracle Banking Credit Facilities Process Management
Oracle Banking Corporate Lending Process Management
Oracle Banking Trade Finance Process Management
Oracle Banking Virtual Account Management
Oracle Banking Supply Chain Finance
Oracle Banking Payments
openEuler
kafka
IBM Qradar SIEM

How to mitigate CVE-2019-12399

Install updates from vendor's website.

Apache Kafka - addressed in versions 2.2.2, 2.3.1
AMQ Streams - update to 1.4.0
IBM Security Guardium Insights - update to 2.0.2
kafka - update to 2.8.2-1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
Oracle Blockchain Platform - update to 21.1.2

External References

Related Security Bulletins