#VU100780 Information disclosure in Apache Kafka Clients - CVE-2024-31141
Published: November 21, 2024 / Updated: February 11, 2025
Apache Kafka Clients
Apache Foundation
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to the way Apache Kafka Clients handles custom configurations. A remote user with access to REST API can read arbitrary files and variables on the system and escalate their privileges filesystem/environment access.