跳转到帖子

Kafka UI Unauthenticated Remote Command Execution via the Groovy Filter option.

recommended_posts

发布于
  • Members

Kafka UI Unauthenticated Remote Command Execution via the Groovy Filter option.

Disclosed
09/27/2023
Created
02/17/2024

Description

A command injection vulnerability exists in Kafka ui between `v0.4.0` and `v0.7.1` allowing an attacker to inject and execute arbitrary shell commands via the `groovy` filter parameter at the `topic` section.

Author(s)

Platform

Linux,Unix

Architectures

cmd, x64, x86

Development

  • Source Code
  • History
  • 查看数 704
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…