CVE-2019-12399

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-12399
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-12399.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-12399
Aliases
Withdrawn
2024-05-08T06:51:13.032748Z
Published
2020-01-14T15:15:12Z
Modified
2023-11-28T17:00:20.156163Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.

References

Affected packages

Git / github.com/apache/kafka

Affected ranges

Type
GIT
Repo
https://github.com/apache/kafka
Events

Affected versions

0.*

0.8.0-beta1
0.8.0-beta1-candidate1

2.*

2.0.0
2.0.0-rc3
2.0.1
2.0.1-rc0
2.1.0
2.1.0-rc1
2.1.1
2.1.1-rc2
2.2.0
2.2.0-rc2