Apache Kafka Version Vulnerability Allowing Arbitrary Configuration Modifications
CVE-2025-27818

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 June 2025

What is CVE-2025-27818?

A security vulnerability allows authenticated users with access to modify Kafka Connect configurations to potentially manipulate SASL JAAS settings. Attackers can exploit this weakness by crafting malicious configurations, resulting in the ability to connect to unauthorized LDAP servers. This can lead to the deserialization of untrusted data and possibly execute harmful Java deserialization chains on the Kafka Connect server. It is essential for administrators to review connector configurations carefully, restrict LDAP settings, and utilize the newly implemented system property to disable vulnerable login modules in order to mitigate these risks effectively.

Affected Version(s)

Apache Kafka 2.3.0 <= 3.9.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ç˝—é‘« <[email protected]>
.
CVE-2025-27818 : Apache Kafka Version Vulnerability Allowing Arbitrary Configuration Modifications