Lucene search

K
nvd[email protected]NVD:CVE-2019-12399
HistoryJan 14, 2020 - 3:15 p.m.

CVE-2019-12399

2020-01-1415:15:12
CWE-319
web.nvd.nist.gov
6

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

48.2%

When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector’s task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.

Affected configurations

Nvd
Node
apachekafkaMatch2.0.0
OR
apachekafkaMatch2.0.1
OR
apachekafkaMatch2.1.0
OR
apachekafkaMatch2.1.1
OR
apachekafkaMatch2.2.0
OR
apachekafkaMatch2.2.1
OR
apachekafkaMatch2.3.0
Node
oraclebanking_corporate_lending_process_managementMatch14.1.0
OR
oraclebanking_corporate_lending_process_managementMatch14.3.0
OR
oraclebanking_corporate_lending_process_managementMatch14.4.0
OR
oraclebanking_credit_facilities_process_managementMatch14.1.0
OR
oraclebanking_credit_facilities_process_managementMatch14.3.0
OR
oraclebanking_credit_facilities_process_managementMatch14.4.0
OR
oraclebanking_liquidity_managementRange14.0.014.4.0
OR
oraclebanking_paymentsMatch14.4.0
OR
oraclebanking_platformMatch2.7.0
OR
oraclebanking_supply_chain_financeRange14.2.014.4.0
OR
oraclebanking_trade_finance_process_managementMatch14.1.0
OR
oraclebanking_trade_finance_process_managementMatch14.3.0
OR
oraclebanking_trade_finance_process_managementMatch14.4.0
OR
oraclebanking_virtual_account_managementMatch14.1.0
OR
oraclebanking_virtual_account_managementMatch14.3.0
OR
oraclebanking_virtual_account_managementMatch14.4.0
OR
oracleblockchain_platformRange<21.1.2
OR
oraclecommunications_cloud_native_core_policyMatch1.9.0
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.68.1.0
OR
oracleflexcube_universal_bankingMatch14.4.0
VendorProductVersionCPE
apachekafka2.0.0cpe:2.3:a:apache:kafka:2.0.0:*:*:*:*:*:*:*
apachekafka2.0.1cpe:2.3:a:apache:kafka:2.0.1:*:*:*:*:*:*:*
apachekafka2.1.0cpe:2.3:a:apache:kafka:2.1.0:*:*:*:*:*:*:*
apachekafka2.1.1cpe:2.3:a:apache:kafka:2.1.1:*:*:*:*:*:*:*
apachekafka2.2.0cpe:2.3:a:apache:kafka:2.2.0:*:*:*:*:*:*:*
apachekafka2.2.1cpe:2.3:a:apache:kafka:2.2.1:*:*:*:*:*:*:*
apachekafka2.3.0cpe:2.3:a:apache:kafka:2.3.0:*:*:*:*:*:*:*
oraclebanking_corporate_lending_process_management14.1.0cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.1.0:*:*:*:*:*:*:*
oraclebanking_corporate_lending_process_management14.3.0cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*
oraclebanking_corporate_lending_process_management14.4.0cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.4.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 271

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

48.2%