Impact
A vulnerability exists in the executeSmartFilterTest function of provectus kafka‑ui that allows arbitrary Groovy code to be injected and executed. The flaw arises from improper handling of user-supplied input, enabling code injection (CWE‑74) and Groovy evaluation injection (CWE‑94). Exploiting this flaw could lead to full compromise of the system running kafka‑ui, impacting confidentiality, integrity, and availability.
Affected Systems
The affected product is provectus kafka‑ui up to and including version 0.7.2. Any installation of these versions is vulnerable; later releases that address the issue are not specified in the data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, but the exploit has been released publicly, meaning an attacker can successfully leverage the flaw. The vulnerability is not listed in the CISA KEV catalog, yet the remote code execution potential and public exploit make the risk significant for exposed deployments.
OpenCVE Enrichment