CVE-2023-34040 is a deserialization vulnerability affecting Spring for Apache Kafka versions 3.0.9 and earlier, and 2.9.10 and earlier. This vulnerability allows for a potential deserialization attack if specific, non-default configurations are enabled and untrusted sources can publish to a Kafka topic. The CVSS score of 7.8 (High) indicates significant potential impact, including high confidentiality, integrity, and availability compromise, though the attack vector requires local access and low privileges. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, with only limited community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.8.1, <= 2.9.10CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* | ||
>= 3.0.0, <= 3.0.9CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.