
Apache Kafka客户端未对用户输入进行严格验证和限制,未经身份验证的攻击者可通过构造恶意配置读取环境变量或磁盘任意内容,或向非预期位置发送请求,提升REST API的文件系统/环境/URL访问权限。
The vulnerabilities and reproduction steps described in this document are for cybersecurity research and educational purposes only. No one may use the information provided in this document for illegal purposes or unauthorized system testing. The author assumes no liability for any direct or indirect damages resulting from the use of the information in this document. If there is any infringement, please contact us promptly so that we can handle and remove the relevant content as soon as possible.
Blog address:
https://blog.csdn.net/xc_214/article/details/148698902?spm=1001.2014.3001.5501
Fenchuan address:
25hvv poc is being updated in real time
https://pc.fenchuan8.com/#/index?forum=101158&yqm=DGR4X

The Apache Kafka client does not strictly validate and restrict user input. An unauthenticated attacker can read environment variables or arbitrary disk content by constructing a malicious configuration, or send requests to unintended locations, thereby elevating the file system/environment/URL access permissions of the REST API.
3.1.0 <= Apache Kafka <= 3.9.0
Slow but 100% accurate; adjust the timeout yourself if a timeout occurs.
