CVE-2017-12610: Apache Kafka

Medium severity, CVSS 6.8. EPSS: 2.9% chance of exploitation in the next 30 days.

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.

Affected products

  • Apache Kafka: from 0.10.0.0, up to and including 0.10.2.1; from 0.11.0.0, up to and including 0.11.0.1

Published 2018-07-26. Last modified 2026-06-17.