CVE-2024-32030 is a critical post-authentication Remote Code Execution (RCE) vulnerability affecting Kafka UI, an open-source web interface for Apache Kafka management. The vulnerability stems from insecure deserialization via the JMX monitoring feature, which uses the RMI protocol. Attackers can exploit this by connecting Kafka UI to a malicious broker, especially if dynamic configuration is enabled or they have access to the Kafka cluster. This allows for RCE with a CVSS score of 8.1 (High), indicating a network-based attack with high impact on confidentiality, integrity, and availability, but requiring high attack complexity. There is no public exploit code or active exploitation reported, and community discussion is minimal, but the high EPSS score suggests a significant threat. Users are strongly advised to upgrade to version 0.7.2 or later, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Provectus | Kafka-Ui | < 0.7.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.