When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
07 Jun 2022, 18:41
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* | |
References | (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory |
20 Apr 2022, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Apr 2022, 15:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.9.0:*:*:*:*:*:*:* | |
References | (MISC) https://www.oracle.com/security-alerts/cpuApr2021.html - Patch, Third Party Advisory | |
References | (N/A) https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/rda253155601968331b5cf0da4f273813bbd91843c2568a8495d1c662@%3Ccommits.kafka.apache.org%3E - Mailing List, Patch, Vendor Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujan2021.html - Patch, Third Party Advisory |
22 Sep 2021, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Jun 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2020-01-14 15:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-12399
Mitre link : CVE-2019-12399
CVE.ORG link : CVE-2019-12399
JSON object : View
Products Affected
oracle
- banking_corporate_lending_process_management
- banking_credit_facilities_process_management
- banking_platform
- financial_services_analytical_applications_infrastructure
- banking_virtual_account_management
- banking_supply_chain_finance
- banking_payments
- communications_cloud_native_core_policy
- flexcube_universal_banking
- banking_liquidity_management
- blockchain_platform
- banking_trade_finance_process_management
apache
- kafka
CWE
CWE-319
Cleartext Transmission of Sensitive Information