CVE-2021-38153
Timing Attack Vulnerability for Apache Kafka Connect and Clients
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
Algunos componentes de Apache Kafka usan "Arrays.equals" para comprender una contraseña o clave, lo cual es vulnerable a ataques de tiempo que hacen que los ataques de fuerza bruta para dichas credenciales tengan más probabilidades de éxito. Los usuarios deben actualizar a la versión 2.8.1 o superior, o a la 3.0.0 o superior, donde se ha corregido esta vulnerabilidad. Las versiones afectadas son Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1 y 2.8.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-06 CVE Reserved
- 2021-09-22 CVE Published
- 2024-06-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (13)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://kafka.apache.org/cve-list | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2021-38153 | 2022-09-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2009041 | 2022-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Kafka Search vendor "Apache" for product "Kafka" | >= 2.0.0 < 2.6.3 Search vendor "Apache" for product "Kafka" and version " >= 2.0.0 < 2.6.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Kafka Search vendor "Apache" for product "Kafka" | >= 2.7.0 < 2.7.2 Search vendor "Apache" for product "Kafka" and version " >= 2.7.0 < 2.7.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Kafka Search vendor "Apache" for product "Kafka" | 2.8.0 Search vendor "Apache" for product "Kafka" and version "2.8.0" | - |
Affected
| ||||||
Quarkus Search vendor "Quarkus" | Quarkus Search vendor "Quarkus" for product "Quarkus" | < 2.2.4 Search vendor "Quarkus" for product "Quarkus" and version " < 2.2.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Brm - Elastic Charging Engine Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine" | < 12.0.0.4.6 Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine" and version " < 12.0.0.4.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Brm - Elastic Charging Engine Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine" | 12.0.0.5.0 Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine" and version "12.0.0.5.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Policy Search vendor "Oracle" for product "Communications Cloud Native Core Policy" | 1.15.0 Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Analytical Applications Infrastructure Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" | >= 8.0.6.0 <= 8.0.9.0 Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.6.0 <= 8.0.9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Analytical Applications Infrastructure Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" | >= 8.1.0.0.0 <= 8.1.20 Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.1.0.0.0 <= 8.1.20" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Behavior Detection Platform Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" | >= 8.0.6.0.0 <= 8.0.8.0 Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" and version " >= 8.0.6.0.0 <= 8.0.8.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Behavior Detection Platform Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" | 8.1.1.0 Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" and version "8.1.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Behavior Detection Platform Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" | 8.1.1.1 Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" and version "8.1.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Behavior Detection Platform Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" | 8.1.2.0 Search vendor "Oracle" for product "Financial Services Behavior Detection Platform" and version "8.1.2.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Enterprise Case Management Search vendor "Oracle" for product "Financial Services Enterprise Case Management" | 8.0.7.1 Search vendor "Oracle" for product "Financial Services Enterprise Case Management" and version "8.0.7.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Enterprise Case Management Search vendor "Oracle" for product "Financial Services Enterprise Case Management" | 8.0.7.2 Search vendor "Oracle" for product "Financial Services Enterprise Case Management" and version "8.0.7.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Enterprise Case Management Search vendor "Oracle" for product "Financial Services Enterprise Case Management" | 8.0.8.0 Search vendor "Oracle" for product "Financial Services Enterprise Case Management" and version "8.0.8.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Enterprise Case Management Search vendor "Oracle" for product "Financial Services Enterprise Case Management" | 8.0.8.1 Search vendor "Oracle" for product "Financial Services Enterprise Case Management" and version "8.0.8.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Enterprise Case Management Search vendor "Oracle" for product "Financial Services Enterprise Case Management" | 8.1.1.0 Search vendor "Oracle" for product "Financial Services Enterprise Case Management" and version "8.1.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Financial Services Enterprise Case Management Search vendor "Oracle" for product "Financial Services Enterprise Case Management" | 8.1.1.1 Search vendor "Oracle" for product "Financial Services Enterprise Case Management" and version "8.1.1.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 18.8 Search vendor "Oracle" for product "Primavera Unifier" and version "18.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 19.12 Search vendor "Oracle" for product "Primavera Unifier" and version "19.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 20.12 Search vendor "Oracle" for product "Primavera Unifier" and version "20.12" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Primavera Unifier Search vendor "Oracle" for product "Primavera Unifier" | 21.12 Search vendor "Oracle" for product "Primavera Unifier" and version "21.12" | - |
Affected
|