CVE-2024-27309: Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.
Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.
When those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.
The incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).
The full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27309?
CVE-2024-27309 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-27309?
To fix CVE-2024-27309, upgrade your Apache Kafka version to 3.6.3 or later.
What is the impact of CVE-2024-27309 on Apache Kafka?
CVE-2024-27309 can lead to improper enforcement of Access Control Lists (ACLs) during migration from ZooKeeper mode to KRaft mode.
Which versions of Apache Kafka are affected by CVE-2024-27309?
All versions of Apache Kafka from 3.5.0 to 3.6.2 are affected by CVE-2024-27309.
What are the conditions to trigger CVE-2024-27309?
CVE-2024-27309 is triggered when an administrator removes an ACL and the resource associated with that ACL is in the process of being migrated.