Apache Kafka Version Vulnerability Allowing Arbitrary Configuration Modifications
CVE-2025-27818

8.8HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 June 2025

What is CVE-2025-27818?

A security vulnerability allows authenticated users with access to modify Kafka Connect configurations to potentially manipulate SASL JAAS settings. Attackers can exploit this weakness by crafting malicious configurations, resulting in the ability to connect to unauthorized LDAP servers. This can lead to the deserialization of untrusted data and possibly execute harmful Java deserialization chains on the Kafka Connect server. It is essential for administrators to review connector configurations carefully, restrict LDAP settings, and utilize the newly implemented system property to disable vulnerable login modules in order to mitigate these risks effectively.

Affected Version(s)

Apache Kafka 2.3.0 <= 3.9.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ç˝—é‘« <[email protected]>
.
CVE-2025-27818 : Apache Kafka Version Vulnerability Allowing Arbitrary Configuration Modifications