Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-14712
HistorySep 22, 2021 - 12:00 a.m.

Apache Kafka timing attack vulnerability

2021-09-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
26
apache kafka
timing attack
vulnerability
real-time data
credential theft
privilege escalation
arrays.equals component
authentication

EPSS

0.002

Percentile

59.8%

Apache Kafka is an open source distributed streaming platform developed by the Apache Software Foundation in the United States. A timing attack vulnerability exists in some versions of Apache Kafka, which enables access to real-time data for building applications that react in real time to changes in the data stream. The vulnerability is primarily due to Kafka’s use of the Arrays.equals component for key or password authentication, which can be used by attackers to brute-force users who use such credentials to authenticate their identities, thereby gaining access to credentials and elevating system privileges.