In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource.
Since Apache Kafka 3.4.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule" is disabled in Apache Kafka 3.4.0, and "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" is disabled by default in in Apache Kafka 3.9.1/4.0.0
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 11 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Apache Apache kafka | |
| CPEs | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | |
| Vendors & Products | Apache Apache kafka | 
Wed, 11 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Tue, 10 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Tue, 10 Jun 2025 08:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource. Since Apache Kafka 3.4.0, we have added a system property ("-Dorg.apache.kafka.disallowed.login.modules") to disable the problematic login modules usage in SASL JAAS configuration. Also by default "com.sun.security.auth.module.JndiLoginModule" is disabled in Apache Kafka 3.4.0, and "com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule" is disabled by default in in Apache Kafka 3.9.1/4.0.0 | |
| Title | Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration | |
| Weaknesses | CWE-502 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published: 2025-06-10T07:54:41.896Z
Updated: 2025-06-10T15:15:58.031Z
Reserved: 2025-03-07T10:02:19.848Z
Link: CVE-2025-27819
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-06-10T14:18:11.943Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-06-10T08:15:22.687
Modified: 2025-07-11T16:52:33.237
Link: CVE-2025-27819
 Redhat
                        Redhat