Description
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1963 | Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0. |
Github GHSA |
GHSA-3j6g-hxx5-3q26 | Observable Discrepancy in Apache Kafka |
References
History
No history.
Subscriptions
Apache
Subscribe
Kafka
Subscribe
Oracle
Subscribe
Communications Brm - Elastic Charging Engine
Subscribe
Communications Cloud Native Core Policy
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Behavior Detection Platform
Subscribe
Financial Services Enterprise Case Management
Subscribe
Primavera Unifier
Subscribe
Quarkus
Subscribe
Quarkus
Subscribe
Redhat
Subscribe
Amq Streams
Subscribe
Camel Quarkus
Subscribe
Integration
Subscribe
Jboss Data Grid
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Service Registry
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T01:37:15.929Z
Reserved: 2021-08-06T00:00:00.000Z
Link: CVE-2021-38153
No data.
Status : Modified
Published: 2021-09-22T09:15:07.847
Modified: 2024-11-21T06:16:30.110
Link: CVE-2021-38153
OpenCVE Enrichment
No data.
EUVD
Github GHSA