• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Critical RCE Vulnerabilities Discovered in Kafka UI

July 22, 2024
in Blockchain
Reading Time: 2min read
0 0
A A
0
Creating Your First GitHub Repository: A Beginner’s Guide
0
SHARES
27
VIEWS
ShareShareShareShareShare


Peter Zhang
Jul 22, 2024 15:37

Researchers identified three critical remote code execution (RCE) vulnerabilities in Kafka UI. Users are advised to upgrade to version 0.7.2 to mitigate risks.





Researchers have uncovered three critical remote code execution (RCE) vulnerabilities in Kafka UI, an open source web application used for managing and monitoring Apache Kafka clusters, according to The GitHub Blog. These vulnerabilities have been addressed in the latest release, version 0.7.2, and users are strongly encouraged to update their systems to mitigate potential exploits.

CVE-2023-52251: RCE via Groovy Script Execution

The first vulnerability, identified as CVE-2023-52251, leverages the message filtering functionality within Kafka UI. Attackers can use the GROOVY_SCRIPT filter type to execute arbitrary Groovy scripts, leading to potential RCE. The exploit can be initiated through a simple HTTP GET request, making it highly accessible. The vulnerability was reported in November 2023 and patched in April 2024.

CVE-2024-32030: RCE via JMX Connector

The second vulnerability, CVE-2024-32030, involves the Java Management Extensions (JMX) connector used by Kafka UI to monitor Kafka brokers. If the dynamic.config.enabled setting is activated, attackers can configure Kafka UI to connect to a malicious JMX server, leading to deserialization attacks. This vulnerability was also fixed in the 0.7.2 release.

CVE-2023-25194: RCE via JndiLoginModule

The third vulnerability, CVE-2023-25194, exploits the JndiLoginModule for authentication. Attackers can manipulate cluster properties to trigger RCE. This issue is only exploitable if the dynamic.config.enabled property is set to true. The fix was included in the 0.7.2 release, prohibiting the use of the JndiLoginModule.

Kafka UI users are advised to upgrade to version 0.7.2 to secure their systems against these critical vulnerabilities. The fixes include updating dependencies and adding stricter controls to prevent potential exploits.

Image source: Shutterstock


Credit: Source link

ShareTweetSendPinShare
Previous Post

Spot Ethereum ETFs Will Draw $1.2 Billion Monthly: Research Firm

Next Post

Don’t Get Shaken Out, Analyst Says Bitcoin And Altcoins Rally Is Just Starting

Next Post
Don’t Get Shaken Out, Analyst Says Bitcoin And Altcoins Rally Is Just Starting

Don’t Get Shaken Out, Analyst Says Bitcoin And Altcoins Rally Is Just Starting

You might also like

Uzbekistan Lures Global Crypto Mining with 10-Year Tax Holiday in New Special Zone

Uzbekistan Lures Global Crypto Mining with 10-Year Tax Holiday in New Special Zone

April 23, 2026
Tron’s Stablecoin Supply Just Hit a Record $86.7 Billion: Is TRX Crypto About to Follow the Liquidity Higher?

Tron’s Stablecoin Supply Just Hit a Record $86.7 Billion: Is TRX Crypto About to Follow the Liquidity Higher?

April 23, 2026
Analyst Who Called Bitcoin’s Top Correctly Now Predicting The Bottom

Analyst Who Called Bitcoin’s Top Correctly Now Predicting The Bottom

April 26, 2026
Shariah-Compliant Stablecoin Moves Into MidEast Arena

Shariah-Compliant Stablecoin Moves Into MidEast Arena

April 24, 2026
XRP Sends Bullish On-Chain Signal Despite Weak Price Action

XRP Sends Bullish On-Chain Signal Despite Weak Price Action

April 24, 2026
Bitfinex Says Expect Bullish Q4 as Bitcoin on Track for Significant Move

Bitcoin’s Bullish Signals Strengthen Despite Recent Hash Rate Dip

April 27, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Bitcoin Large Players Have Built A Sell Wall At $80.5K–$82K – Spoofing Or Structural Supply?

Bitcoin Large Players Have Built A Sell Wall At $80.5K–$82K – Spoofing Or Structural Supply?

April 29, 2026
A Stealth Force In Derivatives—Why Bitcoin Can’t Punch Past $80,000 Yet

A Stealth Force In Derivatives—Why Bitcoin Can’t Punch Past $80,000 Yet

April 29, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.