CVE-2021-38153
published 2021-09-22CVE-2021-38153: Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such…
PriorityP277medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.25%
92.8th percentile
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | kafka | — | — |
| apache | kafka | >= 2.0.0 < 2.6.3 | 2.6.3 |
| apache | kafka | >= 2.7.0 < 2.7.2 | 2.7.2 |
| apache_software_foundation | apache_kafka | Apache Kafka 2.0.x – 2.0.1 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.1.x – 2.1.1 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.2.x – 2.2.2 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.3.x – 2.3.1 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.4.x – 2.4.1 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.5.x – 2.5.1 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.6.x – 2.6.2 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.7.x – 2.7.1 | — |
| apache_software_foundation | apache_kafka | Apache Kafka 2.8.x – 2.8.0 | — |
| oracle | communications_brm_elastic_charging_engine | < 12.0.0.4.6 | 12.0.0.4.6 |
| oracle | communications_brm_elastic_charging_engine | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6.0 – 8.0.9.0 | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.1.0.0.0 – 8.1.20 | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_behavior_detection_platform | 8.0.6.0.0 – 8.0.8.0 | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect use of Arrays.equals for password/key comparison in Apache Kafka components (Connect and Clients), which is vulnerable to timing attacks enabling brute force credential attacks ↗
- →Monitor for repeated authentication attempts against Apache Kafka Connect or Kafka Clients endpoints — timing attack exploitation may manifest as statistically anomalous patterns in authentication response times or high-volume credential guessing ↗
- →Upstream fix commits for 2.8.1 branch can be used as patch-diffing reference to identify the vulnerable code path: kafka clients fix at commit 3325342fecba56c2f5b28d60ca37605a7ebf420a and kafka connect fix at commit d7abd32f3569a65a4b59c7dd8a655b17ffa1b455 ↗
- →Upstream fix commits for 3.0.0 branch: kafka clients at 00c086e9087c3163cb0502bf0067bae4d401d66e and kafka connect at be5889d1d110abfd2f580d88b109a9a0c8e7b2d6 — use for patch-diffing to identify vulnerable vs. fixed code ↗
- ·Affected Apache Kafka versions span 2.0.0 through 2.8.0; fixed in 2.8.1 and 3.0.0. Deployments running any version in this range for Kafka Connect or Kafka Clients are vulnerable. ↗
- ·The kafka-clients package in Red Hat build of Quarkus, Red Hat Decision Manager 7, Red Hat Integration Camel Quarkus 1, Red Hat Integration Service Registry, Red Hat Process Automation 7, and streams for Apache Kafka are all confirmed affected. ↗
- ·openshift-logging/elasticsearch6-rhel8 and openshift4/ose-logging-elasticsearch6 are confirmed NOT affected despite being in the same ecosystem. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vulncheck5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Notifications (Apache Kafka) — CVE-2021-38153
vendor_oracle·2022-07-15·CVSS 5.9
CVE-2021-38153 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Notifications (Apache Kafka) — CVE-2021-38153
Oracle Oracle Communications Applications Risk Matrix: Notifications (Apache Kafka) vulnerability
CVE: CVE-2021-38153
CVSS: 5.9
Protocol: TCP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Apache Kafka) — CVE-2021-38153
vendor_oracle·2022-04-15·CVSS 5.9
CVE-2021-38153 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (Apache Kafka) — CVE-2021-38153
Oracle Oracle Communications Risk Matrix: Policy (Apache Kafka) vulnerability
CVE: CVE-2021-38153
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Event Streams and Communications (Apache Kafka) — CVE-2021-38153
vendor_oracle·2022-01-15·CVSS 5.9
CVE-2021-38153 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Event Streams and Communications (Apache Kafka) — CVE-2021-38153
Oracle Oracle Construction and Engineering Risk Matrix: Event Streams and Communications (Apache Kafka) vulnerability
CVE: CVE-2021-38153
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients
vendor_redhat·2021-09-21·CVSS 5.9
CVE-2021-38153 [MEDIUM] CWE-367 Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients
Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: kafka-clients (Red Hat build of Quarkus) - Affected
Package: kafka-clients (Red Hat Decision Manager 7) - Affected
Package: ka
OSV
Observable Discrepancy in Apache Kafka
osv·2021-09-23
CVE-2021-38153 [MEDIUM] Observable Discrepancy in Apache Kafka
Observable Discrepancy in Apache Kafka
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
GHSA
Observable Discrepancy in Apache Kafka
ghsa·2021-09-23
CVE-2021-38153 [MEDIUM] CWE-203 Observable Discrepancy in Apache Kafka
Observable Discrepancy in Apache Kafka
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
OSV
CVE-2021-38153: Some components in Apache Kafka use `Arrays
osv·2021-09-22·CVSS 5.9
CVE-2021-38153 [MEDIUM] CVE-2021-38153: Some components in Apache Kafka use `Arrays
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
VulnCheck
Apache kafka Observable Discrepancy
vulncheck·2021·CVSS 5.9
CVE-2021-38153 [MEDIUM] Apache kafka Observable Discrepancy
Apache kafka Observable Discrepancy
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
Affected: Apache kafka
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.cloudflare.com/ddos-threat-report-2023-q1/
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-38153 Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients
bugzilla·2021-09-29·CVSS 5.9
CVE-2021-38153 [MEDIUM] CVE-2021-38153 Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients
CVE-2021-38153 Kafka: Timing Attack Vulnerability for Apache Kafka Connect and Clients
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
References:
https://kafka.apache.org/cve-list
Discussion:
Upstream fix:
[2.8.1]
kafka clients - https://github.com/apache/kafka/commit/3325342fecba56c2f5b28d60ca37605a7ebf420a
kafka connect - https://github.com/apache/kafka/
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
blogs_tenable·2022-04-20
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
arxiv_fulltext·2023-08-23
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
M. Mehdi Kholoosi12,
M. Ali Babar12,
Cemal Yilmaz3
1 School of Computer Science, CREST, The University of Adelaide, Adelaide, Australia
2 Cyber Security Cooperative Research Centre, Australia
3 Faculty of Engineering and Natural Sciences, Sabanci University, Istanbul, 34956, Turkey
Emails: [email protected], [email protected], [email protected]
## Abstract
Timing attacks are considered one of the most damaging side-channel attacks. These attacks exploit timing fluctuations caused by certain operations to disclose confidential information to an attacker. For instance, in asymmetric encryption, operations such as multiplication and division can cause time-varying execution times th
https://kafka.apache.org/cve-listhttps://lists.apache.org/thread.html/r26390c8b09ecfa356582d665b0c01f4cdcf16ac047c85f9f9f06a88c%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r26390c8b09ecfa356582d665b0c01f4cdcf16ac047c85f9f9f06a88c%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r35322aec467ddae34002690edaa4d9f16e7df9b5bf7164869b75b62c%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r45cc0602d5f2cbb72e48896dfadf5e5b87ed85630449598b40e8f0be%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r45cc0602d5f2cbb72e48896dfadf5e5b87ed85630449598b40e8f0be%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rd9ef217b09fdefaf32a4e1835b59b96629542db57e1f63edb8b006e6%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rd9ef217b09fdefaf32a4e1835b59b96629542db57e1f63edb8b006e6%40%3Cusers.kafka.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://kafka.apache.org/cve-listhttps://lists.apache.org/thread.html/r26390c8b09ecfa356582d665b0c01f4cdcf16ac047c85f9f9f06a88c%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r26390c8b09ecfa356582d665b0c01f4cdcf16ac047c85f9f9f06a88c%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r35322aec467ddae34002690edaa4d9f16e7df9b5bf7164869b75b62c%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r45cc0602d5f2cbb72e48896dfadf5e5b87ed85630449598b40e8f0be%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/r45cc0602d5f2cbb72e48896dfadf5e5b87ed85630449598b40e8f0be%40%3Cusers.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rd9ef217b09fdefaf32a4e1835b59b96629542db57e1f63edb8b006e6%40%3Cdev.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rd9ef217b09fdefaf32a4e1835b59b96629542db57e1f63edb8b006e6%40%3Cusers.kafka.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-09-22
Published
Exploited in the wild