Information Exposure Through Timing Discrepancy in Apache Kafka - CVE-2021-38153

 

Information Exposure Through Timing Discrepancy in Apache Kafka - CVE-2021-38153

Published: September 21, 2021


Vulnerability identifier: #VU56790
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38153
CWE-ID: CWE-208
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

the vulnerability exists due to some components in Apache Kafka use "Arrays.equals" to validate a password or key, which is vulnerable to timing attacks. A local user can abuse the "Arrays.equals" to brute force access credentials and escalate privileges on the system.


Affected software

Apache Kafka
IBM Operator for Apache Flink
Red Hat Integration Camel Extensions for Quarkus
Netcool Operations Insight
Spectrum Discover
Oracle Financial Services Enterprise Case Management
Oracle Financial Services Behavior Detection Platform
Red Hat Integration - Service Registry
Log Analysis
Red Hat Integration Camel-K
IBM Cloud Pak for Multicloud Management Monitoring
AMQ Streams
Oracle Communications Cloud Native Core Policy
Vert.x
IBM Qradar SIEM
JBoss Data Grid
Oracle Financial Services Analytical Applications Infrastructure
IBM Security Verify Information Queue
IBM Sterling Order Management
IBM Security Guardium
Oracle Communications BRM - Elastic Charging Engine
Primavera Unifier
IBM Tivoli Network Manager (ITNM)

How to mitigate CVE-2021-38153

Install updates from vendor's website.

Apache Kafka - update to 2.8.1
IBM Operator for Apache Flink - update to 1.4.5
Netcool Operations Insight - update to 1.6.5
AMQ Streams - addressed in versions 1.6.6, 2.0.0
Vert.x - update to 4.2.5
JBoss Data Grid - update to 8.3.1
IBM Security Verify Information Queue - update to 10.0.5
Oracle Communications BRM - Elastic Charging Engine - update to 12.0.0.5.1
Red Hat Integration - Service Registry - update to 1
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF003
Red Hat Integration Camel-K - update to 1.8
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
IBM Sterling Order Management - update to 10.0.0.29

External References

Related Security Bulletins