VDB

CVE-2022-34917

CVE-2022-34917 PUBLISHED CVSS 7.5 HIGH

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException and causing denial of service. Example scenarios: - Kafka cluster without authentication: Any clients able to establish a network connection to a broker can trigger the issue. - Kafka cluster with SASL authentication: Any clients able to establish a network connection to a broker, without the need for valid SASL credentials, can trigger the issue. - Kafka cluster with TLS authentication: Only clients able to successfully authenticate via TLS can trigger the issue. We advise the users to upgrade the Kafka installations to one of the 3.2.3, 3.1.2, 3.0.2, 2.8.2 versions.

EPSS 1.31% · 68.7th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.31%
68.7th percentile

Affected Products

VendorProductVersions
Bitnamikafka3.2.0, 2.8.0, 3.0.0
Bitnamikafka3.0.0, 3.1.0, 3.2.0

Timeline

  • Sep 19, 2022 CVE Published
  • Sep 21, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Dec 20, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Mar 20, 2023 EPSS Score
  • May 3, 2023 EPSS Score
  • Jun 17, 2023 EPSS Score
  • Aug 1, 2023 EPSS Score
  • Sep 15, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
  • Dec 14, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›