Vulnerability identifier: #VU56790
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-208
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Apache Kafka
Client/Desktop applications /
Messaging software
Vendor: Apache Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
the vulnerability exists due to some components in Apache Kafka use "Arrays.equals" to validate a password or key, which is vulnerable to timing attacks. A local user can abuse the "Arrays.equals" to brute force access credentials and escalate privileges on the system.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Apache Kafka: 2.7.0 - 2.7.1, 2.6.0 - 2.6.2, 2.8.0, 2.5.0 - 2.5.1, 2.4.0 - 2.4.1, 2.2.0 - 2.2.2, 2.3.0 - 2.3.1, 2.1.0 - 2.1.1, 2.0.0 - 2.0.1
CPE
External links
http://seclists.org/oss-sec/2021/q3/184
http://kafka.apache.org/cve-list
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?