CVE-2017-12610: Medium severity apache kafka vulnerability
In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12610?
CVE-2017-12610 is a vulnerability in Apache Kafka where authenticated clients can use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations.
How does CVE-2017-12610 impact Apache Kafka?
CVE-2017-12610 allows authenticated Kafka clients to impersonate other users.
What is the severity of CVE-2017-12610?
The severity of CVE-2017-12610 is medium with a CVSS score of 6.8.
Which versions of Apache Kafka are affected by CVE-2017-12610?
Apache Kafka versions 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1 are affected by CVE-2017-12610.
How can I fix CVE-2017-12610 in Apache Kafka?
To fix CVE-2017-12610, upgrade Apache Kafka to a version that is not affected by the vulnerability.