Weakness in Apache Kafka Connect May Expose Plaintext Secrets
CVE-2019-12399
What is CVE-2019-12399?
In certain versions of Apache Kafka Connect, a configuration mismanagement issue can lead to the exposure of plaintext secrets. When Connect workers are set up with one or more configuration providers, any externalized secret variable included in connector property values may inadvertently be exposed. This occurs when a client can request access to a connector's task configuration, allowing sensitive information to be reflected in the response instead of the intended secret variables. Users of the affected versions should ensure proper configuration and consider upgrading to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kafka Apache Kafka 2.0.0
Kafka 2.0.1
Kafka 2.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved