Impact
CMAK versions up to 3.0.0.6 fail to install a cross-site request forgery filter, allowing attackers to perform state‑changing actions on behalf of authenticated operators. An attacker can craft a hidden form that submits to destructive endpoints such as topic deletion or cluster reconfiguration, using the operator’s HTTP Basic authentication credentials or session cookie without SameSite protection.
Affected Systems
The vulnerability affects Yahoo’s CMAK product version 3.0.0.6 and earlier releases. Deployments of these versions that expose the administrative UI to the internet are susceptible to exploitation.
Risk and Exploitability
The CVSS score is 7.2, indicating that the vulnerability carries a high severity level. However, the EPSS score of less than 1% suggests that the likelihood of active exploitation is currently low and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires a victim to be authenticated (via Basic auth or a cookie) and relies on a cross‑site request to be submitted by a malicious site. If these conditions are met, an attacker can carry out destructive operations without the victim’s knowledge.
OpenCVE Enrichment