CVE编号
CVE-2018-1288利用情况
暂无补丁情况
N/A披露时间
2018-07-27漏洞描述
Apache Kafka是美国阿帕奇(Apache)软件基金会开发的一个开源的分布式流媒体平台。该平台能够获取实时数据,用于构建对数据流的变化进行实时反应的应用程序。Apache Kafka 0.9.0.0版本至0.9.0.1版本,0.10.0.0版本至0.10.2.1版本,0.11.0.0版本至0.11.0.2版本,1.0.0版本中存在安全绕过漏洞。攻击者可通过发送特制的请求(干扰到数据的复制)利用该漏洞造成数据丢失。
解决建议
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:https://lists.apache.org/thread.html/29f61337323f48c47d4b41d74b9e452bd60e65d0e5103af9a6bb2fef@%3Cusers.kafka.apache.org%3E
参考链接 |
|
---|---|
http://www.securityfocus.com/bid/104900 | |
https://access.redhat.com/errata/RHSA-2018:3768 | |
https://lists.apache.org/thread.html/29f61337323f48c47d4b41d74b9e452bd60e65d0... | |
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d... | |
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a... | |
https://lists.apache.org/thread.html/d1581fb6464c9bec8a72575c01f5097d68e2fbb2... | |
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34... | |
https://lists.apache.org/thread.html/r07e1bbd1643847d599feb34c707906a4fdcc81e... | |
https://lists.apache.org/thread.html/r35322aec467ddae34002690edaa4d9f16e7df9b... | |
https://www.oracle.com/security-alerts/cpujul2020.html |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | apache | kafka | * |
From (excluding) 0.9.0.0 |
Up to (including) 0.9.0.1 |
||||
运行在以下环境 | |||||||||
应用 | apache | kafka | * |
From (including) 0.10.0.0 |
Up to (including) 0.10.2.1 |
||||
运行在以下环境 | |||||||||
应用 | apache | kafka | * |
From (including) 0.11.0.0 |
Up to (including) 0.11.0.2 |
||||
运行在以下环境 | |||||||||
应用 | apache | kafka | 1.0.0 | - | |||||
运行在以下环境 | |||||||||
应用 | redhat | jboss_middleware_text-only_advisories | 1.0 | - | |||||
运行在以下环境 | |||||||||
系统 | alpine_3.10 | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.11 | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.12 | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.13 | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.8 | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.9 | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_edge | php7 | * |
Up to (excluding) 7.2.8-r0 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | php7 | * |
Up to (excluding) 7.2.8-1.5.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_10 | php7 | * |
Up to (excluding) 7.4.0-6 |
|||||
运行在以下环境 | |||||||||
系统 | debian_11 | php7 | * |
Up to (excluding) 8.4.0-4 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | php7 | * |
Up to (excluding) 6.3.0-18+deb9u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_sid | php7 | * |
Up to (excluding) 8.4.0-4 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.0 | php7 | * |
Up to (excluding) 7.2.5-lp150.2.6.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_42.3 | php7 | * |
Up to (excluding) 7.0.7-40.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_11_SP4 | php7 | * |
Up to (excluding) 5.3.17-112.28.1 |
|||||
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 低
- 影响范围 未更改
- 用户交互 无
- 可用性 低
- 保密性 无
- 完整性 低
还没有评论,来说两句吧...