¡¾Îó²îͨ¸æ¡¿Apache Kafka Connect LDAPÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2025-27818)
Ðû²¼Ê±¼ä 2025-06-10Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache Kafka Connect LDAPÔ¶³Ì´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-27818 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-06-10 |
Îó²îÆÀ·Ö | ÔÝÎÞ | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache KafkaÊÇÒ»¸ö¿ªÔ´µÄÂþÑÜʽÁ÷´¦Öóͷ£Æ½Ì¨£¬Ö÷ÒªÓÃÓÚ¸ßÍÌÍ¡¢¿ÉÀ©Õ¹µÄÐÂÎÅÐû²¼Óë¶©ÔÄ¡£ËüÖ§³ÖʵʱÊý¾Ý´«Ê䣬¿ÉÆÕ±éÓ¦ÓÃÓÚÈÕÖ¾ÍøÂç¡¢ÊÂÎñ¼à¿Ø¡¢Á÷ʽÅÌËãµÈ³¡¾°¡£Kafka ͨ¹ýProducer¡¢BrokerºÍConsumer¹¹½¨ÐÂÎŹܵÀ£¬¾ß±¸³¤ÆÚ»¯¡¢¸ß¿ÉÓúÍÈÝ´íÄÜÁ¦£¬ÆÕ±éÓÃÓÚ´óÊý¾ÝºÍ΢·þÎñ¼Ü¹¹ÖС£
2025Äê6ÔÂ10ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½ApacheÐû²¼µÄÇ徲ͨ¸æ£¬Åû¶Apache Kafka±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¨CVE-2025-27818£©¡£¹¥»÷Õß¿Éͨ¹ýKafka ConnectÉèÖÃÖеÄsasl.jaas.config²ÎÊý£¬½«Kafka¿Í»§¶ËÖ¸Ïò¶ñÒâLDAP·þÎñÆ÷£¬ÓÕµ¼·þÎñÆ÷·´ÐòÁл¯²»¿ÉÐÅÊý¾Ý£¬´Ó¶øÊµÏÖí§Òâ´úÂëÖ´ÐС£¸ÃÎó²îÓ°ÏìʹÓÃSASL JAASÉèÖõÄKafka Connect¼¯Èº£¬ÌØÊâÊÇÔÚδ¶ÔµÇ¼ģ¿é¾ÙÐÐÏÞÖÆÉèÖõÄÇéÐÎÖС£×ÔKafka 3.9.1/4.0.0Æð£¬¹Ù·½ÒÑĬÈϽûÓÃÏà¹Ø¸ßΣº¦µÇ¼ģ¿é£¬²¢ÌṩϵͳÊôÐÔÓÃÓÚϸ»¯¿ØÖÆ¡£½¨ÒéÓû§ÊµÊ±Éý¼¶ÊÜÓ°Ïì°æ±¾£¬Ç¿»¯ÉèÖÃÉ󼯣¬½µµÍΣº¦¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://kafka.apache.org/downloads/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£


¾©¹«Íø°²±¸11010802024551ºÅ