CVE Vulnerabilities

CVE-2018-1288

Published: Jul 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Ubuntu

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Affected Software

Name Vendor Start Version End Version
Kafka Apache 0.9.0.0 (excluding) 0.9.0.1 (including)
Kafka Apache 0.10.0.0 (including) 0.10.2.1 (including)
Kafka Apache 0.11.0.0 (including) 0.11.0.2 (including)
Kafka Apache 1.0.0 (including) 1.0.0 (including)
Red Hat Fuse 7.2 RedHat kafka *

References