Unknown
CVE-2019-12399
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-12399
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector’s task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Products
- banking corporate lending process management 14.1.0,
- banking corporate lending process management 14.3.0,
- banking corporate lending process management 14.4.0,
- banking credit facilities process management 14.1.0,
- banking credit facilities process management 14.3.0,
- banking credit facilities process management 14.4.0,
- banking liquidity management,
- banking payments 14.4.0,
- banking platform 2.7.0,
- banking supply chain finance,
- banking trade finance process management 14.1.0,
- banking trade finance process management 14.3.0,
- banking trade finance process management 14.4.0,
- banking virtual account management 14.1.0,
- banking virtual account management 14.3.0,
- banking virtual account management 14.4.0,
- blockchain platform,
- communications cloud native core policy 1.9.0,
- financial services analytical applications infrastructure,
- flexcube universal banking 14.4.0,
- kafka 2.0.0,
- kafka 2.0.1,
- kafka 2.1.0,
- kafka 2.1.1,
- kafka 2.2.0,
- kafka 2.2.1,
- kafka 2.3.0
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: