CVE-2019-12399: Apache Kafka
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.
Affected products
- Apache Kafka: version 2.0.0 only; version 2.0.1 only; version 2.1.0 only; version 2.1.1 only; version 2.2.0 only; version 2.2.1 only; …
- Oracle Banking Corporate Lending Process Management: version 14.1.0 only; version 14.3.0 only; version 14.4.0 only
- Oracle Banking Credit Facilities Process Management: version 14.1.0 only; version 14.3.0 only; version 14.4.0 only
- Oracle Banking Liquidity Management: from 14.0.0, up to and including 14.4.0
- Oracle Banking Payments: version 14.4.0 only
- Oracle Banking Platform: version 2.7.0 only
- Oracle Banking Supply Chain Finance: from 14.2.0, up to and including 14.4.0
- Oracle Banking Trade Finance Process Management: version 14.1.0 only; version 14.3.0 only; version 14.4.0 only
- Oracle Banking Virtual Account Management: version 14.1.0 only; version 14.3.0 only; version 14.4.0 only
- Oracle Blockchain Platform: before 21.1.2 (fixed in 21.1.2)
- Oracle Communications Cloud Native Core Policy: version 1.9.0 only
- Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.1.0
- Oracle Flexcube Universal Banking: version 14.4.0 only
Published 2020-01-14. Last modified 2026-06-17.