-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.kafka:kafka | maven | >= 0.11.0.0, <= 2.1.0 | 2.1.1 |
The vulnerability centers on improper ACL validation for transactional/idempotent Produce requests. Analysis of Kafka's architecture indicates:
Ongoing coverage of React2Shell