cbcvebase.
CVE-2021-38153
published 2021-09-22

CVE-2021-38153: Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such…

PriorityP277medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.25%
92.8th percentile
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
apachekafka
apachekafka>= 2.0.0 < 2.6.32.6.3
apachekafka>= 2.7.0 < 2.7.22.7.2
apache_software_foundationapache_kafkaApache Kafka 2.0.x – 2.0.1
apache_software_foundationapache_kafkaApache Kafka 2.1.x – 2.1.1
apache_software_foundationapache_kafkaApache Kafka 2.2.x – 2.2.2
apache_software_foundationapache_kafkaApache Kafka 2.3.x – 2.3.1
apache_software_foundationapache_kafkaApache Kafka 2.4.x – 2.4.1
apache_software_foundationapache_kafkaApache Kafka 2.5.x – 2.5.1
apache_software_foundationapache_kafkaApache Kafka 2.6.x – 2.6.2
apache_software_foundationapache_kafkaApache Kafka 2.7.x – 2.7.1
apache_software_foundationapache_kafkaApache Kafka 2.8.x – 2.8.0
oraclecommunications_brm_elastic_charging_engine< 12.0.0.4.612.0.0.4.6
oraclecommunications_brm_elastic_charging_engine
oraclecommunications_cloud_native_core_policy
oraclefinancial_services_analytical_applications_infrastructure8.0.6.0 – 8.0.9.0
oraclefinancial_services_analytical_applications_infrastructure8.1.0.0.0 – 8.1.20
oraclefinancial_services_behavior_detection_platform
oraclefinancial_services_behavior_detection_platform
oraclefinancial_services_behavior_detection_platform
oraclefinancial_services_behavior_detection_platform8.0.6.0.0 – 8.0.8.0
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management
oraclefinancial_services_enterprise_case_management

Detection & IOCsextracted from sources · hover to see the quote

  • Detect use of Arrays.equals for password/key comparison in Apache Kafka components (Connect and Clients), which is vulnerable to timing attacks enabling brute force credential attacks
  • Monitor for repeated authentication attempts against Apache Kafka Connect or Kafka Clients endpoints — timing attack exploitation may manifest as statistically anomalous patterns in authentication response times or high-volume credential guessing
  • Upstream fix commits for 2.8.1 branch can be used as patch-diffing reference to identify the vulnerable code path: kafka clients fix at commit 3325342fecba56c2f5b28d60ca37605a7ebf420a and kafka connect fix at commit d7abd32f3569a65a4b59c7dd8a655b17ffa1b455
  • Upstream fix commits for 3.0.0 branch: kafka clients at 00c086e9087c3163cb0502bf0067bae4d401d66e and kafka connect at be5889d1d110abfd2f580d88b109a9a0c8e7b2d6 — use for patch-diffing to identify vulnerable vs. fixed code
  • ·Affected Apache Kafka versions span 2.0.0 through 2.8.0; fixed in 2.8.1 and 3.0.0. Deployments running any version in this range for Kafka Connect or Kafka Clients are vulnerable.
  • ·The kafka-clients package in Red Hat build of Quarkus, Red Hat Decision Manager 7, Red Hat Integration Camel Quarkus 1, Red Hat Integration Service Registry, Red Hat Process Automation 7, and streams for Apache Kafka are all confirmed affected.
  • ·openshift-logging/elasticsearch6-rhel8 and openshift4/ose-logging-elasticsearch6 are confirmed NOT affected despite being in the same ecosystem.

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vulncheck5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.