CVE-2024-27309: Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode

Published Apr 12, 2024
·
Updated

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.

Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.

When those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.

The incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).

The full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.

Affected Software

2 affected componentsFixes available
maven/org.apache.kafka:kafka-metadata>=3.5.0<3.6.2
3.6.2
Apache Kafka>=3.5.0<=3.6.1

Event History

Apr 12, 2024
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:33 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-27309?

CVE-2024-27309 has been classified as a medium severity vulnerability.

2

How do I fix CVE-2024-27309?

To fix CVE-2024-27309, upgrade your Apache Kafka version to 3.6.3 or later.

3

What is the impact of CVE-2024-27309 on Apache Kafka?

CVE-2024-27309 can lead to improper enforcement of Access Control Lists (ACLs) during migration from ZooKeeper mode to KRaft mode.

4

Which versions of Apache Kafka are affected by CVE-2024-27309?

All versions of Apache Kafka from 3.5.0 to 3.6.2 are affected by CVE-2024-27309.

5

What are the conditions to trigger CVE-2024-27309?

CVE-2024-27309 is triggered when an administrator removes an ACL and the resource associated with that ACL is in the process of being migrated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203