CVE-2023-25194 is a critical vulnerability in Apache Kafka Connect API, allowing authenticated operators to achieve remote code execution (RCE) by manipulating connector configurations. An attacker can leverage specific Kafka client SASL JAAS configuration properties to trigger JNDI injection, leading to deserialization of untrusted data and RCE if vulnerable gadget chains are present. This vulnerability carries a CVSS score of 8.8 (High) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, its high EPSS score (0.94055) and the existence of Metasploit modules and Nuclei templates indicate a high likelihood of exploitation, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, <= 3.3.2CPE matchmatch criteria | cpe:2.3:a:apache:kafka_connect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.