CVE-2024-8285
Published: Aug 30, 2024
Modified: Nov 20, 2025
CVSS v3.1
5.9
Description
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the attacker needs to perform a Man-in-the-Middle attack or compromise any external systems, such as DNS or network routing configuration. This issue is considered a high complexity attack, with additional high privileges required, as the attack would need access to the Kroxylicious configuration or a peer system. The result of a successful attack impacts both data integrity and confidentiality.
| Vendor | Product | Versions |
|---|---|---|
Unknown | kroxylicious | affected 0.80.0 - < 0.80.0 |
Red Hat | Streams for Apache Kafka 2.8.0 | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Red Hat | streams for Apache Kafka | All versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now