#VU56790 Information Exposure Through Timing Discrepancy in Apache Kafka


Published: 2021-09-21

Vulnerability identifier: #VU56790

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2021-38153

CWE-ID: CWE-208

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Apache Kafka
Client/Desktop applications / Messaging software

Vendor: Apache Foundation

Description

The vulnerability allows a local user to escalate privileges on the system.

the vulnerability exists due to some components in Apache Kafka use "Arrays.equals" to validate a password or key, which is vulnerable to timing attacks. A local user can abuse the "Arrays.equals" to brute force access credentials and escalate privileges on the system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Apache Kafka: 2.7.0 - 2.7.1, 2.6.0 - 2.6.2, 2.8.0, 2.5.0 - 2.5.1, 2.4.0 - 2.4.1, 2.2.0 - 2.2.2, 2.3.0 - 2.3.1, 2.1.0 - 2.1.1, 2.0.0 - 2.0.1


CPE

External links
http://seclists.org/oss-sec/2021/q3/184
http://kafka.apache.org/cve-list


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability