CVE-2025-27817. Apache Kafka客户端未对用户输入进行严格验证和限制,未经身份验证的攻击者可通过构造恶意配置读取环境变量或磁盘任意内容,或向非预期位置发送请求,提升REST API的文件系统/环境/URL访问权限。

github.com/iSee857/CVE-2025-27817

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.