CVE-2018-17196
Improper Input Validation in Apache Kafka
8.8
HIGH
CVSS 3.1
EPSS 0.21%
Description
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
How to fix CVE-2018-17196
To remediate CVE-2018-17196, upgrade the affected package to a fixed version below.
- —upgrade to 2.1.1 or later
Is CVE-2018-17196 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.11.0.0, < 2.1.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |