Vulnerability Database

309,961

Total vulnerabilities in the database

CVE-2017-12610

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.

CVSS v2:

  • Severity: Low
  • Score: 4.9
  • AV:N/AC:M/Au:S/C:P/I:P/A:N