Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

Second Bitcoin ETF issuer predicts BTC hitting $1M

May 9, 2026

Bollinger Bands Creator Has Just Gone All In On Bitcoin, Is $100,000 Next?

May 9, 2026

Bank of Canada to bring stablecoin rules in 2027 with US Clarity Act on the brink of stalling

May 9, 2026
Facebook X (Twitter) Instagram
Saturday, May 9 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Critical RCE Vulnerabilities Discovered in Kafka UI

July 22, 2024Updated:July 22, 2024No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Critical RCE Vulnerabilities Discovered in Kafka UI
Share
Facebook Twitter LinkedIn Pinterest Email
ad


Peter Zhang
Jul 22, 2024 15:37

Researchers recognized three crucial distant code execution (RCE) vulnerabilities in Kafka UI. Customers are suggested to improve to model 0.7.2 to mitigate dangers.





Researchers have uncovered three crucial distant code execution (RCE) vulnerabilities in Kafka UI, an open supply internet software used for managing and monitoring Apache Kafka clusters, in accordance with The GitHub Weblog. These vulnerabilities have been addressed within the newest launch, model 0.7.2, and customers are strongly inspired to replace their programs to mitigate potential exploits.

CVE-2023-52251: RCE through Groovy Script Execution

The primary vulnerability, recognized as CVE-2023-52251, leverages the message filtering performance inside Kafka UI. Attackers can use the GROOVY_SCRIPT filter sort to execute arbitrary Groovy scripts, resulting in potential RCE. The exploit will be initiated by way of a easy HTTP GET request, making it extremely accessible. The vulnerability was reported in November 2023 and patched in April 2024.

CVE-2024-32030: RCE through JMX Connector

The second vulnerability, CVE-2024-32030, includes the Java Administration Extensions (JMX) connector utilized by Kafka UI to watch Kafka brokers. If the dynamic.config.enabled setting is activated, attackers can configure Kafka UI to connect with a malicious JMX server, resulting in deserialization assaults. This vulnerability was additionally fastened within the 0.7.2 launch.

CVE-2023-25194: RCE through JndiLoginModule

The third vulnerability, CVE-2023-25194, exploits the JndiLoginModule for authentication. Attackers can manipulate cluster properties to set off RCE. This situation is simply exploitable if the dynamic.config.enabled property is about to true. The repair was included within the 0.7.2 launch, prohibiting using the JndiLoginModule.

Kafka UI customers are suggested to improve to model 0.7.2 to safe their programs towards these crucial vulnerabilities. The fixes embrace updating dependencies and including stricter controls to forestall potential exploits.

Picture supply: Shutterstock


ad
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

Second Bitcoin ETF issuer predicts BTC hitting $1M

May 9, 2026

It might be too late for bitcoin’s quantum migration, Project Eleven report argues

May 9, 2026

Why a 2017 Linux bug is now a major concern for the crypto industry

May 9, 2026

Bankers are scrambling as Senate schedules CLARITY Act markup for May 14

May 9, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
Second Bitcoin ETF issuer predicts BTC hitting $1M
May 9, 2026
Bollinger Bands Creator Has Just Gone All In On Bitcoin, Is $100,000 Next?
May 9, 2026
Bank of Canada to bring stablecoin rules in 2027 with US Clarity Act on the brink of stalling
May 9, 2026
It might be too late for bitcoin’s quantum migration, Project Eleven report argues
May 9, 2026
Stablecoin execs warn on hard part ahead
May 9, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.