Confluent's vulnerability footprint is concentrated in its Ansible-based deployment and configuration automation tooling, where the durable signal centers on access-control weaknesses such as incorrect default permissions and missing authorization checks. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Confluent over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33924CRITICAL Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access se | Sep 29, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-33923MEDIUM Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database). | Sep 29, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Confluent.
Media articles that mention a CVE ID that affects a product developed by Confluent — matched by CVE ID, not by vendor name.