SCA: security update for org.apache.kafka:kafka (GHSA-c9h3-c6qj-hh7q)

high Tenable Self-Hosted Container Security Plugin ID 413800

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The
vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers.
This can lead to brokers hitting OutOfMemoryException and causing denial of service. Example scenarios: -
Kafka cluster without authentication: Any clients able to establish a network connection to a broker can
trigger the issue. - Kafka cluster with SASL authentication: Any clients able to establish a network
connection to a broker, without the need for valid SASL credentials, can trigger the issue. - Kafka
cluster with TLS authentication: Only clients able to successfully authenticate via TLS can trigger the
issue. We advise the users to upgrade the Kafka installations to one of the 3.2.3, 3.1.2, 3.0.2, 2.8.2
versions. (CVE-2022-34917)

See Also

https://github.com/advisories/GHSA-c9h3-c6qj-hh7q

Plugin Details

Severity: High

ID: 413800

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2022-34917

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/21/2022

Vulnerability Publication Date: 9/20/2022

Reference Information

CVE: CVE-2022-34917