Impact
An unauthenticated user who can reach the Kafka Connect REST API can configure a non‑secure HTTP Event Collector endpoint. This is a Server‑Side Request Forgery (CWE‑918) vulnerability. When the connector sends data, it transmits authentication credentials to the attacker‑controlled server, potentially exposing credentials that compromise all data sent through the connector. The impact includes credential exposure, possible data compromise, and limited alteration of event delivery, with the severity indicated by a CVSS score of 8.2.
Affected Systems
The vulnerability affects Splunk Connect for Kafka products released before version 2.2.7, including all earlier builds of the Splunk Connect for Kafka app.
Risk and Exploitability
The high CVSS score reflects significant risk, and the exploit requires unauthenticated access to the Kafka Connect REST API. If that API is exposed to an attacker, the SSRF can be triggered to any external server, causing credentials to leak. No EPSS data is available and the vulnerability is not listed as a known exploited vulnerability in CISA’s KEV catalog, but the potential for credential theft and data compromise makes it a high‑priority risk. The likely attack vector is internal or compromised systems with network access to the REST API.
OpenCVE Enrichment