SCA: security update for org.apache.kafka:kafka_2.12, org.apache.kafka:kafka_2.13 (GHSA-76qp-h5mr-frr4)

high Tenable Cloud Security Plugin ID 436365

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A possible security vulnerability has been identified in Apache Kafka. This requires access to a
alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors
on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been
possible on Kafka clusters since Apache Kafka 2.0.0 (Kafka Connect 2.3.0). When configuring the broker via
config file or AlterConfig command, or connector via the Kafka Kafka Connect REST API, an authenticated
operator can set the `sasl.jaas.config` property for any of the connector's Kafka clients to
"com.sun.security.auth.module.LdapLoginModule", which can be done via the
`producer.override.sasl.jaas.config`, `consumer.override.sasl.jaas.config`, or
`admin.override.sasl.jaas.config` properties. This will allow the server to connect to the attacker's LDAP
server and deserialize the LDAP response, which the attacker can use to execute java deserialization
gadget chains on the Kafka connect server. Attacker can cause unrestricted deserialization of untrusted
data (or) RCE vulnerability when there are gadgets in the classpath. Since Apache Kafka 3.0.0, users are
allowed to specify these properties in connector configurations for Kafka Connect clusters running with
out-of-the-box configurations. Before Apache Kafka 3.0.0, users may not specify these properties unless
the Kafka Connect cluster has been reconfigured with a connector client override policy that permits them.
Since Apache Kafka 3.9.1/4.0.0, we have added a system property
("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL
JAAS configuration. Also by default
"com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" are disabled
in Apache Kafka Connect 3.9.1/4.0.0. We advise the Kafka users to validate connector configurations and
only allow trusted LDAP configurations. Also examine connector dependencies for vulnerable versions and
either upgrade their connectors, upgrading that specific dependency, or removing the connectors as options
for remediation. Finally, in addition to leveraging the "org.apache.kafka.disallowed.login.modules" system
property, Kafka Connect users can also implement their own connector client config override policy, which
can be used to control which Kafka client properties can be overridden directly in a connector config and
which cannot. (CVE-2025-27818)

See Also

https://github.com/advisories/GHSA-76qp-h5mr-frr4

Plugin Details

Severity: High

ID: 436365

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 12/12/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.83

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-27818

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/10/2025

Vulnerability Publication Date: 6/10/2025

Reference Information

CVE: CVE-2025-27818

cwe: CWE-502