← Back to CVE List

CVE-2018-17196

Published: 2019-07-11T21:15Z
Last Modified: 2024-11-21T03:54Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt