CVE Vulnerabilities

CVE-2018-1288

Published: Jul 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Affected Software

NameVendorStart VersionEnd Version
KafkaApache0.9.0.0 (excluding)0.9.0.1 (including)
KafkaApache0.10.0.0 (including)0.10.2.1 (including)
KafkaApache0.11.0.0 (including)0.11.0.2 (including)
KafkaApache1.0.0 (including)1.0.0 (including)
Red Hat Fuse 7.2RedHatkafka*

References