VDB
CVE-2023-34040
CVE-2023-34040
PUBLISHED
Es existiert eine Schwachstelle in VMware Tanzu Spring Framework for Apache Kafka. Diese ist auf eine unsichere Deserialsierung von Objekten zurückzuführen. Eine erfolgreiche Ausnutzung der Schwachstelle ist an einige Vorbedingungen geknüpft, welche erfüllt sein müssen um eine Ausnutzung möglich zu machen. Ein lokaler Angreifer kann diese Schwachstelle ausnutzen, um unbekannte Auswirkungen zu verursachen, potenziell Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.
EPSS 21.41% · 95.8th percentile
Risk Scores
EPSS Score
21.41%
95.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | IBM QRadar SIEM 7.5 |
Exploit Intelligence
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD (github-poc-repo)
- huyennhat-dev/cve-2023-34040 (github-poc-repo)
…and 66 more exploits
Timeline
- Aug 24, 2023 CVE Published
- Aug 24, 2023 PoC Published
- Aug 25, 2023 EPSS Score
- Aug 30, 2023 PoC Published
- Aug 31, 2023 PoC Published
- Sep 17, 2023 PoC Published
- Sep 18, 2023 PoC Published
- Sep 18, 2023 PoC Published
- Sep 29, 2023 PoC Published
- Sep 30, 2023 PoC Published
- Sep 30, 2023 PoC Published
- Oct 7, 2023 PoC Published