CVE-2017-12610

Severity
6.8MEDIUM
EPSS
0.4%
top 41.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages3 packages

Mavenorg.apache.kafka:kafka-clients0.10.0.00.10.2.2+1
NVDapache/kafka0.10.0.00.10.2.1+1
CVEListV5apache_software_foundation/apache_kafka0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.1+1

🔴Vulnerability Details

3
GHSA
Improper Authentication in Apache Kafka2022-05-13
OSV
Improper Authentication in Apache Kafka2022-05-13
CVEList
CVE-2017-12610: In Apache Kafka 02018-07-26

📋Vendor Advisories

1
Red Hat
kafka: Clients authenticated with SASL/PLAIN or SASL/SCRAM can impersonate other users2018-07-26

💬Community

1
Bugzilla
CVE-2017-12610 kafka: Clients authenticated with SASL/PLAIN or SASL/SCRAM can impersonate other users2018-08-02
CVE-2017-12610 (MEDIUM CVSS 6.8) | In Apache Kafka 0.10.0.0 to 0.10.2. | cvebase.io