GHSA-26f8-x7cc-wqpc
HIGHCVE-2023-25194A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters since Apache Kafka Connect 2.3.0. When configuring the connector via the Kafka Connec
- Affected
- >= 2.3.0, < 3.4.0
- Fixed in
- 3.4.0
- Weakness
- CWE-502
- Published
- 2023-02-07
- Source
- github