⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2023-25194

Severity
8.8HIGH
EPSS
94.1%
top 0.10%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedFeb 7
Latest updateJun 10

Description

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters since Apache Kafka Connect 2.3.0. When configuring the connector via the Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config` property for any of the connect

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Mavenorg.apache.kafka:connect2.3.03.4.0
NVDapache/kafka_connect2.3.03.3.2
CVEListV5apache_software_foundation/apache_kafka2.0.03.3.2

🔴Vulnerability Details

5
GHSA
Apache Kafka Deserialization of Untrusted Data vulnerability2025-06-10
GHSA
Apache Kafka Connect vulnerable to Deserialization of Untrusted Data2023-02-07
OSV
Apache Kafka Connect vulnerable to Deserialization of Untrusted Data2023-02-07
CVEList
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect2023-02-07
VulnCheck
Apache kafka_connect Deserialization of Untrusted Data2023

💥Exploits & PoCs

1
Nuclei
Apache Druid Kafka Connect - Remote Code Execution

📋Vendor Advisories

5
Red Hat
org.apache.kafka: Kafka JNDI Login Module RCE Vulnerability2025-06-10
Oracle
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Kafka) — CVE-2023-251942024-01-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Notification (Apache Kafka) — CVE-2023-251942023-07-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: IDM - Authentication (Apache Kafka) — CVE-2023-251942023-04-15
Red Hat
kafka: RCE/DoS via SASL JAAS JndiLoginModule configuration in Kafka Connect2023-02-07
CVE-2023-25194 (HIGH CVSS 8.8) | A possible security vulnerability h | cvebase.io