SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-38153

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful.

MEDIUM 5.9EPSS 6.25%

Does this matter?

Lower severity and a low EPSS score (6.25%). Track it; it rarely justifies an emergency change on its own.

Description

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
6.25% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
apache/kafka · quarkus/quarkus · oracle/communications brm - elastic charging engine · oracle/communications cloud native core policy · oracle/financial services analytical applications infrastructure · oracle/financial services behavior detection platform · oracle/financial services enterprise case management · oracle/primavera unifier
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.