CVE-2018-1288
26.07.2018, 14:29
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.Enginsight
Vendor | Product | Version |
---|---|---|
apache | kafka | 0.9.0.0 < 𝑥 ≤ 0.9.0.1 |
apache | kafka | 0.10.0.0 ≤ 𝑥 ≤ 0.10.2.1 |
apache | kafka | 0.11.0.0 ≤ 𝑥 ≤ 0.11.0.2 |
apache | kafka | 1.0.0 |
redhat | jboss_middleware_text-only_advisories | 1.0 |
oracle | database | 11.2.0.4 |
oracle | database | 12.1.0.2 |
oracle | database | 12.2.0.1 |
oracle | primavera_p6_enterprise_project_portfolio_management | 19.12.0.0 ≤ 𝑥 ≤ 19.12.6.0 |
oracle | timesten_in-memory_database | 𝑥 < 18.1.2.1.0 |
𝑥
= Vulnerable software versions
References