https://seclists.org/oss-sec/2024/q2/105: CVE-2024-27309: Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
Published Apr 12, 2024
·Updated
Affected Software
1 affected component
Apache Kafka
Frequently Asked Questions
1
What is the severity of CVE-2024-27309?
CVE-2024-27309 is rated as a medium severity vulnerability due to potential incorrect access control during migration.
2
How do I fix CVE-2024-27309?
To fix CVE-2024-27309, you should ensure that you follow the recommended migration guidelines provided by Apache Kafka.
3
What are the potential impacts of CVE-2024-27309?
The potential impacts of CVE-2024-27309 include unauthorized access and data exposure during the migration from ZooKeeper to KRaft mode.
4
In which versions of Apache Kafka is CVE-2024-27309 applicable?
CVE-2024-27309 is applicable to versions of Apache Kafka that are transitioning from ZooKeeper mode to KRaft mode.
5
Is there a workaround for CVE-2024-27309?
Currently, there are no specific workarounds for CVE-2024-27309; the recommended approach is to implement the migration with caution.