Impact
The vulnerability in Klaw arises from inconsistent handling of username case sensitivity during registration and login. This flaw permits an attacker to trigger a targeted denial of service by locking a user’s account permanently. The resulting impact is limited to the affected account’s availability; it does not expose data or elevate privileges. The flaw is associated with CWE‑178 and CWE‑20.
Affected Systems
The issue affects the Aiven‑Open Klaw application, a self‑service Apache Kafka topic management portal. All releases prior to version 2.10.4 of Klaw are vulnerable. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity. EPSS is not available, so the precise likelihood of exploitation cannot be quantified, but the flaw can be exercised by any actor who can access the login interface. The vulnerability is not listed in CISA’s KEV catalog, and no additional exploitation prerequisites are described, suggesting that an attacker can trigger the DoS simply by sending requests that exploit the case‑sensitivity mismatch. The patch released in 2.10.4 removes the inconsistency and resolves the lockout behavior.
OpenCVE Enrichment