CVE-2018-1288

Description

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS Score
Exploitation Probability
0.688

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1288 are fixed in Apache-kafka 0.10.2.2Windows
Vulnerabilities CVE-2018-1288 are fixed in Apache-kafka 0.11.0.3Windows
Vulnerabilities CVE-2018-1288 are fixed in Apache-kafka 1.0.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.2Windows
Vulnerabilities CVE-2018-1288 are fixed in Apache-kafka for Linux 0.10.2.2Linux
Vulnerabilities CVE-2018-1288 are fixed in Apache-kafka for Linux 0.11.0.3Linux
Vulnerabilities CVE-2018-1288 are fixed in Apache-kafka for Linux 1.0.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234