CVE-2021-38153: Timing Attack Vulnerability for Apache Kafka Connect and Clients
Apache Kafka could allow a remote attacker to obtain sensitive information, caused by a timing attack flaw due to the use of "Arrays.equals" to validate a password or key. By utilizing brute-force attack techniques, an attacker could exploit this vulnerability to obtain credentials information, and use this information to launch further attacks against the affected system.
Other sources
Some components in Apache Kafka use Arrays.equals to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.kafka:kafka-clientsto a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
maven/org.apache.kafka:kafka-clientsto a version that resolves this vulnerability.Fixed in 2.7.2 - Upgrade
Upgrade
maven/org.apache.kafka:kafka-clientsto a version that resolves this vulnerability.Fixed in 2.6.3 - Upgrade
Upgrade
maven/org.apache.kafka:kafka_2.13to a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
maven/org.apache.kafka:kafka_2.13to a version that resolves this vulnerability.Fixed in 2.7.2 - Upgrade
Upgrade
maven/org.apache.kafka:kafka_2.13to a version that resolves this vulnerability.Fixed in 2.6.3 - Upgrade
Upgrade
maven/org.apache.kafka:kafka_2.12to a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
maven/org.apache.kafka:kafka_2.12to a version that resolves this vulnerability.Fixed in 2.7.2 - Upgrade
Upgrade
maven/org.apache.kafka:kafka_2.12to a version that resolves this vulnerability.Fixed in 2.6.3 - Upgrade
Upgrade
redhat/kafka-2.8.1 kafka-clientsto a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
Apache Kafkato a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
Apache Kafkato a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-38153?
The severity of CVE-2021-38153 is medium.
Which components in Apache Kafka are vulnerable to CVE-2021-38153?
Some components in Apache Kafka are vulnerable to CVE-2021-38153.
How can I fix CVE-2021-38153?
To fix CVE-2021-38153, users should upgrade to Apache Kafka 2.8.1 or higher, or 3.0.0 or higher.
Where can I find more information about CVE-2021-38153?
You can find more information about CVE-2021-38153 at the following references: [link1](https://www.cve.org/CVERecord?id=CVE-2021-38153), [link2](https://nvd.nist.gov/vuln/detail/CVE-2021-38153), [link3](https://bugzilla.redhat.com/show_bug.cgi?id=2009041), [link4](https://access.redhat.com/errata/RHSA-2022:0219).