CVE-2018-1288

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
apachekafka
0.9.0.0 <
𝑥
≤ 0.9.0.1
apachekafka
0.10.0.0 ≤
𝑥
≤ 0.10.2.1
apachekafka
0.11.0.0 ≤
𝑥
≤ 0.11.0.2
apachekafka
1.0.0
redhatjboss_middleware_text-only_advisories
1.0
oracledatabase
11.2.0.4
oracledatabase
12.1.0.2
oracledatabase
12.2.0.1
oracleprimavera_p6_enterprise_project_portfolio_management
19.12.0.0 ≤
𝑥
≤ 19.12.6.0
oracletimesten_in-memory_database
𝑥
< 18.1.2.1.0
𝑥
= Vulnerable software versions
References