ZeroHour

CVE-2018-1288

CVSS 3.1
5.4 medium
EPSS
5%p91
Published
()
Modified
Description

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Vendors
apacheredhatoracle
Products
kafka, jboss middleware text-only advisories, database, primavera p6 enterprise project portfolio management, timesten in-memory database
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

In the news

No ingested article mentions this CVE yet.