CVE-2019-12399

CVSS V2 Medium 5 CVSS V3 High 7.5
Description
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.
Overview
  • CVE ID
  • CVE-2019-12399
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2020-01-14T15:15:12
  • Last Modified Date
  • 2022-06-07T18:41:50
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:kafka:2.0.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:kafka:2.0.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:kafka:2.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:kafka:2.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:kafka:2.2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:kafka:2.2.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:kafka:2.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_liquidity_management:*:*:*:*:*:*:*:* 1 OR 14.0.0 14.4.0
cpe:2.3:a:oracle:banking_payments:14.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_supply_chain_finance:*:*:*:*:*:*:*:* 1 OR 14.2.0 14.4.0
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_virtual_account_management:14.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:banking_virtual_account_management:14.4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* 1 OR 21.1.2
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.9.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:* 1 OR 8.0.6 8.1.0
cpe:2.3:a:oracle:flexcube_universal_banking:14.4.0:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:N/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • NONE
  • Availability Impact
  • NONE
  • Base Score
  • 5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 10
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • NONE
  • Base Score
  • 7.5
  • Base Severity
  • HIGH
  • Exploitability Score
  • 3.9
  • Impact Score
  • 3.6
References
Reference URL Reference Tags
https://lists.apache.org/thread.html/r6af5ed95726874e9add022955be83c192428c248d1c9a1914aff89d9%40%3Cdev.kafka.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r6af5ed95726874e9add022955be83c192428c248d1c9a1914aff89d9@%3Cusers.kafka.apache.org%3E Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2020/01/14/1 Mailing List Third Party Advisory
https://lists.apache.org/thread.html/r6af5ed95726874e9add022955be83c192428c248d1c9a1914aff89d9@%3Cannounce.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rc27d424d0bdeaf31081c3e246db3c66e882243ae3f342dfa845e0261@%3Ccommits.kafka.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rde947ee866de6687bc51cdc8dfa6d7e6b3ad4ce8c708c344f773e6dc@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r4b20b40c40d4a4c641e2ef4228098a57935e5782bfdfdf3650e48265@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r6fa1cff4786dcef2ddd1d717836ef123c878e8321c24855bad24ae0f@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r3203d7f25a6ca56ff3e48c43a6aa7cb60b8e5d57d0eed9f76dc2b7a8@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r0e3a613705d70950aca2bfe9a6265c87503921852d9a3dbce512ca9f@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r4d9e87cdae99e98d7b244cfa53d9d2532d368d3a187fbc87c493dcbe@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r801c68bf987931f35d2e24ecc99f3aa2850fdd8f5ef15fe6c60fecf3@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/rfe90ca0463c199b99c2921410639aed53a172ea8b733eab0dc776262@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r3154f5adbc905f1f9012a92240c8e00a96628470cc819453b9606d0e@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r56eb055b544931451283fee51f7e1f5b8ebd3085fed7d77aaba504c9@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r9871a4215b621c1d09deee5eba97f0f44fde01b4363deb1bed0dd160@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r47c225db363d1ee2c18c4b3b2f51b63a9789f78c7fa602e5976ecd05@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r2d390dec5f360ec8aa294bef18e1a4385e2a3698d747209216f5a48b@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://lists.apache.org/thread.html/r8890b8f18f1de821595792b58b968a89692a255bc20d86d395270740@%3Ccommits.druid.apache.org%3E Mailing List Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html Patch Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://lists.apache.org/thread.html/rda253155601968331b5cf0da4f273813bbd91843c2568a8495d1c662@%3Ccommits.kafka.apache.org%3E Mailing List Patch Vendor Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
History
Created Old Value New Value Data Type Notes
2022-04-20 17:00:13 Added to TrackCVE
2022-12-04 09:21:41 2020-01-14T15:15Z 2020-01-14T15:15:12 CVE Published Date updated
2022-12-04 09:21:41 2022-06-07T18:41:50 CVE Modified Date updated
2022-12-04 09:21:41 Analyzed Vulnerability Status updated