CVE-2018-17196
published 2019-07-11CVE-2018-17196: In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation…
PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
5.48%
91.9th percentile
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | kafka | — | — |
| apache | kafka | 0.11.0.0 – 2.1.0 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Core (Apache Kafka) — CVE-2018-17196
vendor_oracle·2020-10-15·CVSS 7.0
CVE-2018-17196 [HIGH] Oracle Oracle Construction and Engineering Risk Matrix: Core (Apache Kafka) — CVE-2018-17196
Oracle Oracle Construction and Engineering Risk Matrix: Core (Apache Kafka) vulnerability
CVE: CVE-2018-17196
CVSS: 7.0
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Web Access (kafka client) — CVE-2018-17196
vendor_oracle·2020-07-15·CVSS 8.8
CVE-2018-17196 [HIGH] Oracle Oracle Construction and Engineering Risk Matrix: Web Access (kafka client) — CVE-2018-17196
Oracle Oracle Construction and Engineering Risk Matrix: Web Access (kafka client) vulnerability
CVE: CVE-2018-17196
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
kafka: potential to bypass transaction/idempotent ACL checks
vendor_redhat·2019-07-11·CVSS 8.8
CVE-2018-17196 [HIGH] CWE-20 kafka: potential to bypass transaction/idempotent ACL checks
kafka: potential to bypass transaction/idempotent ACL checks
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
A flaw was found in Apache Kafka. This flaw allows authorized clients with write permissions to manually craft a Produce request, which can bypass transaction/idempotent ACL checks.
Package: kafka (Red Hat Fuse 7) - Not affected
Package: kafka (Red Hat JBoss Fuse 6) - Not affected
Package: kafka (Red Hat Mobile Application Platform 4) - Out of support scope
Package: kafka (Red H
OSV
Improper Input Validation in Apache Kafka
osv·2022-05-24
CVE-2018-17196 [HIGH] Improper Input Validation in Apache Kafka
Improper Input Validation in Apache Kafka
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
GHSA
Improper Input Validation in Apache Kafka
ghsa·2022-05-24
CVE-2018-17196 [HIGH] CWE-20 Improper Input Validation in Apache Kafka
Improper Input Validation in Apache Kafka
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/109139https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/d1581fb6464c9bec8a72575c01f5097d68e2fbb230aff24622622a58%40%3Ccommits.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r66de86b9a608c1da70b2d27d765c11ec88edf6e5dd6f379ab33e072a%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc20d86d395270740%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc27d424d0bdeaf31081c3e246db3c66e882243ae3f342dfa845e0261%40%3Ccommits.kafka.apache.org%3Ehttps://www.mail-archive.com/dev%40kafka.apache.org/msg99277.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://www.securityfocus.com/bid/109139https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/d1581fb6464c9bec8a72575c01f5097d68e2fbb230aff24622622a58%40%3Ccommits.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r66de86b9a608c1da70b2d27d765c11ec88edf6e5dd6f379ab33e072a%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc20d86d395270740%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc27d424d0bdeaf31081c3e246db3c66e882243ae3f342dfa845e0261%40%3Ccommits.kafka.apache.org%3Ehttps://www.mail-archive.com/dev%40kafka.apache.org/msg99277.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-07-11
Published