cbcvebase.
CVE-2018-1288
published 2018-07-26

CVE-2018-1288: In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker…

medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachekafka<= 0.9.0.1
apachekafka
apachekafka0.10.0.0 – 0.10.2.1
apachekafka0.11.0.0 – 0.11.0.2
apache_software_foundationapache_kafka
apache_software_foundationapache_kafka
apache_software_foundationapache_kafka
apache_software_foundationapache_kafka
oracledatabase
oracledatabase
oracledatabase
oracledatabase
oracledatabase
oracleprimavera_p6_enterprise_project_portfolio_management19.12.0.0 – 19.12.6.0
oracletimesten_in-memory_database< 18.1.2.1.018.1.2.1.0
redhatjboss_middleware_text-only_advisories