SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Apache Kafka Client Arbitrary File Read SSRF

Category: WEB-ATTACKS      

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or sending requests to an unintended location.


Relevant Information