CVE-2018-1288

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:kafka:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*

Information

Published : 2018-07-26 14:29

Updated : 2021-10-07 16:15


NVD link : CVE-2018-1288

Mitre link : CVE-2018-1288


JSON object : View

Products Affected

redhat

  • jboss_middleware_text-only_advisories

apache

  • kafka
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor