CVE-2025-27819
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource. Since Apache Kafka 3.4.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule" is disabled in Apache Kafka 3.4.0, and "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" is disabled by default in in Apache Kafka 3.9.1/4.0.0
EPSS 0.90% · 76.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | kafka | 2.0.0 |
| Bitnami | kafka | 2.0.0 |
Timeline
- Jun 9, 2025 PoC Published
- Jun 9, 2025 PoC Published
- Jun 9, 2025 CVE Published
- Jun 10, 2025 EPSS Score
- Jun 10, 2025 PoC Published
- Jun 10, 2025 PoC Published
- Jun 10, 2025 PoC Published
- Jun 18, 2025 Coalition ESS Score
- Jun 20, 2025 EPSS Score
- Jul 1, 2025 EPSS Score
- Jul 11, 2025 EPSS Score
- Jul 11, 2025 Coalition ESS Score