Bug 2327264 (CVE-2024-31141)
| Summary: | CVE-2024-31141 kafka-clients: privilege escalation to filesystem read-access via automatic ConfigProvider | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anstephe, aprice, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, brian.stansberry, caswilli, ccranfor, cdewolf, chazlett, chfoley, clement.escoffier, cmah, cmiranda, dandread, darran.lofthouse, dhanak, dkreling, dosoudil, eric.wittmann, fjuma, fmariani, fmongiar, gmalinko, gsmet, ibek, istudens, ivassile, iweiss, janstey, jcantril, jmartisk, jnethert, jpechane, jpoth, jrokos, jsamir, kaycoth, kholdawa, kverlaen, lcouzens, lgao, lthon, manderse, mnovotny, mosmerov, mpierce, mskarbek, msochure, msvehla, nipatil, nwallace, oezr, olubyans, pantinor, pcongius, pdelbell, pesilva, pgallagh, pjindal, pmackay, probinso, rguimara, rkubis, rojacob, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, sdouglas, smaestri, sthirugn, swoodman, tcunning, tom.jenkinson, tqvarnst, vkrizan, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in Apache Kafka Clients. Apache Kafka Clients accepts configuration data for customizing behavior and includes ConfigProvider plugins to manipulate these configurations. Apache Kafka also provides FileConfigProvider, DirectoryConfigProvider, and EnvVarConfigProvider implementations, which include the ability to read from disk or environment variables. In applications where an untrusted party can specify Apache Kafka Clients configurations, attackers may use these ConfigProviders to read arbitrary contents of the disk and environment variables.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2024-11-19 09:01:00 UTC
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.8 for Spring Boot Via RHSA-2024:10700 https://access.redhat.com/errata/RHSA-2024:10700 This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 Via RHSA-2024:10861 https://access.redhat.com/errata/RHSA-2024:10861 This issue has been addressed in the following products: Streams for Apache Kafka 2.9.0 Via RHSA-2025:2416 https://access.redhat.com/errata/RHSA-2025:2416 This issue has been addressed in the following products: Streams for Apache Kafka 2.9.1 Via RHSA-2025:9922 https://access.redhat.com/errata/RHSA-2025:9922 This issue has been addressed in the following products: Streams for Apache Kafka 3.0.0 Via RHSA-2025:12511 https://access.redhat.com/errata/RHSA-2025:12511 |