Description
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- Spring / Spring for Apache Kafka4.1.0 – 4.1.0
- Spring / Spring for Apache Kafka4.0.0 – 4.0.6
- Spring / Spring for Apache Kafka3.0.0 – 3.3.16
- Spring / Spring for Apache Kafka2.9.0 – 2.9.14
- Spring / Spring for Apache Kafka0 – 2.8.12
- vmware / spring_for_apache_kafka2.8.13
References
Updated 20m ago · 8 sources