Spring For Apache Kafka VMware Spring For Apache Kafka

Do you want an email whenever new security vulnerabilities are reported in VMware Spring For Apache Kafka?

By the Year

In 2024 there have been 0 vulnerabilities in VMware Spring For Apache Kafka . Last year Spring For Apache Kafka had 1 security vulnerability published. Right now, Spring For Apache Kafka is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 7.80
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Spring For Apache Kafka vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent VMware Spring For Apache Kafka Security Vulnerabilities

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier

CVE-2023-34040 7.8 - High - August 24, 2023

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record.

Marshaling, Unmarshaling

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for VMware Spring For Apache Kafka or by VMware? Click the Watch button to subscribe.

VMware
Vendor

subscribe