CVE-2024-31141
Last modified
CVE-2024-31141 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these configurations. Apache Kafka also provides FileConfigProvider, DirectoryConfigProvider, and EnvVarConfigProvider implementations which include the ability to read from disk or environment variables. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use these ConfigProviders to read arbitrary contents of the disk and environment variables. In particular, this flaw may be used in Apache Kafka Connect to escalate from REST API access to filesystem/environment access, which may be undesirable in certain environments, including SaaS products. This issue affects Apache Kafka Clients: from 2.3.0 through 3.5.2, 3.6.2, 3.7.0. Users with affected applications are recommended to upgrade kafka-clients to version >=3.8.0, and set the JVM system property "org.apache.kafka.automatic.config.providers=none". Users of Kafka Connect with one of the listed ConfigProvider implementations specified in their worker config are also recommended to add appropriate "allowlist.pattern" and "allowed.paths" to restrict their operation to appropriate bounds. For users of Kafka Clients or Kafka Connect in environments that trust users with disk and environment variable access, it is not recommended to set the system property. For users of the Kafka Broker, Kafka MirrorMaker 2.0, Kafka Streams, and Kafka command-line tools, it is not recommended to set the system property.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these configurations. Apache Kafka also provides FileConfigProvider, DirectoryConfigProvider, and EnvVarConfigProvider implementations which include the ability to read from disk or environment variables. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use these ConfigProviders to read arbitrary contents of the disk and environment variables. In particular, this flaw may be used in Apache Kafka Connect to escalate from REST API access to filesystem/environment access, which may be undesirable in certain environments, including SaaS products. This issue affects Apache Kafka Clients: from 2.3.0 through 3.5.2, 3.6.2, 3.7.0. Users with affected applications are recommended to upgrade kafka-clients to version >=3.8.0, and set the JVM system property "org.apache.kafka.automatic.config.providers=none". Users of Kafka Connect with one of the listed ConfigProvider implementations specified in their worker config are also recommended to add appropriate "allowlist.pattern" and "allowed.paths" to restrict their operation to appropriate bounds. For users of Kafka Clients or Kafka Connect in environments that trust users with disk and environment variable access, it is not recommended to set the system property. For users of the Kafka Broker, Kafka MirrorMaker 2.0, Kafka Streams, and Kafka command-line tools, it is not recommended to set the system property.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Kafka | >= 2.3.0, <= 3.5.2 |
| Apache | Kafka | >= 3.6.0, <= 3.6.2 |
| Apache | Kafka | 3.7.0 |
References
- https://lists.apache.org/thread/9whdzfr0zwdhr364604w5ssnzmg4v2lvMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/11/18/5Mailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20250131-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-31141?
How severe is CVE-2024-31141?
How do I fix CVE-2024-31141?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-31136In JetBrains TeamCity before 2024.03 2FA could be bypassed b…7.4
- CVE-2024-31137In JetBrains TeamCity before 2024.03 reflected XSS was possi…6.1
- CVE-2024-31138In JetBrains TeamCity before 2024.03 xSS was possible via Ag…5.4
- CVE-2024-31139In JetBrains TeamCity before 2024.03 xXE was possible in the…8.1
- CVE-2024-3114An issue was discovered in GitLab CE/EE affecting all versio…6.5
- CVE-2024-31140In JetBrains TeamCity before 2024.03 server administrators c…4.9
- CVE-2024-31142Because of a logical error in XSA-407 (Branch Type Confusion…7.5
- CVE-2024-31143An optional feature of PCI MSI called "Multiple Message" all…7.5
- CVE-2024-31144For a brief summary of Xapi terminology, see: https://xa…3.8
- CVE-2024-31145Certain PCI devices in a system might be assigned Reserved M…7.5
- CVE-2024-31146When multiple devices share resources and one of them is to …7.5
- CVE-2024-3115An issue was discovered in GitLab EE affecting all versions …4.3
Are you affected by CVE-2024-31141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
