- Description
- In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource. Since Apache Kafka 3.4.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule" is disabled in Apache Kafka 3.4.0, and "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" is disabled by default in in Apache Kafka 3.9.1/4.0.0
- Source
- security@apache.org
- NVD status
- Analyzed
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- security@apache.org
- CWE-502
- Hype score
- Not currently trending
CVE-2025-27819 Remote Code Execution in Apache Kafka via SASL JAAS JndiLoginModu... https://t.co/AhzOYyd9e1 Vulnerability Alert Subscriptions: https://t.co/hrQhy5uz4x
@VulmonFeeds
10 Jun 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨🚨Apache Kafka multiple high-risk vulnerabilities CVE-2025-27817: Apache Kafka Client Arbitrary File Read Vulnerability CVE-2025-27818, CVE-2025-27819: Apache Kafka #RCE Vulnerability ZoomEye Dork👉app="Kafka" Reveals 10k+ vulnerable instances! ZoomEye Link: https://t.c
@zoomeye_team
10 Jun 2025
819 Impressions
5 Retweets
17 Likes
6 Bookmarks
0 Replies
0 Quotes
CVE-2025-27819 In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is v… https://t.co/kXQlNMS9Rn
@CVEnew
10 Jun 2025
338 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBFF1223-11B1-4E7A-9538-A6F6FD024ECB",
"versionEndIncluding": "3.3.2",
"versionStartIncluding": "2.0.0"
}
],
"operator": "OR"
}
]
}
]