CVE-2018-1288 describes a vulnerability in Apache Kafka versions 0.9.0.0 through 1.0.0, affecting Apache, Oracle, and Red Hat distributions. Authenticated Kafka users can exploit this flaw by crafting specific fetch requests, allowing them to perform actions typically restricted to the Kafka Broker. This unauthorized interference with data replication can lead to data loss. The vulnerability has a CVSS score of 5.4 (Medium), indicating it can be exploited remotely with low complexity by an authenticated attacker, potentially causing low impact to integrity and availability. Despite its potential for data loss, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
> 0.9.0.0, <= 0.9.0.1CPE matchmatch criteria | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | ||
>= 0.10.0.0, <= 0.10.2.1CPE matchmatch criteria | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | ||
>= 0.11.0.0, <= 0.11.0.2CPE matchmatch criteria | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:apache:kafka:1.0.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.