CVE-2021-38153
Timing Attack Vulnerability for Apache Kafka Connect and Clients
5.9
MEDIUM
CVSS 3.1
EPSS 5.8%
Description
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
How to fix CVE-2021-38153
To remediate CVE-2021-38153, upgrade the affected package to a fixed version below.
- —upgrade to 2.6.3 or later
- —upgrade to 2.6.3 or later
- —no fix listed
- —upgrade to 2.6.3 or later
- —upgrade to 2.6.3 or later
Is CVE-2021-38153 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (5)
- >= 2.0.0, < 2.6.3, >= 2.7.0, < 2.7.2, >= 2.8.0, < 2.8.1
- >= 2.0.0, < 2.6.3
- >= 2.0.0, <= 2.4.1
- >= 2.0.0, < 2.6.3
- >= 2.4.0, < 2.6.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |