CVE-2018-1288 PUBLISHED

Reported by apache · Published July 26, 2018

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Affected Products

VendorProductVersions
Apache Software FoundationApache Kafka0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2
Apache Software FoundationApache Kafka1.0.0, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2
Mavenorg.apache.kafka:kafka0, 0

Timeline

References

Open in Interactive Console →