Database/Control plane, storage & DevOps
Apache Kafka (client): ConfigProvider plugins let an untrusted app read files/env of the Kafka client host
CVSS 6.5CVE-2024-31141Control plane, storage & DevOpscurated
Impact
ConfigProvider plugins let an untrusted app read files/env of the Kafka client host
Who can reach it
Network (remote)
What to do
Control-plane: dependency upgrade in telemetry/billing pipelines
References
Related entries
- Apache Kafka (client): SASL/OAUTHBEARER endpoint URLs accept file://CVE-2025-27817 · Apache Kafka (client)High
- Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINOCVE-2024-32048 · Intel Distribution of OpenVINO Model ServerMedium
- GitLab EE: crafted SCIM provisioning input triggers an unbounded loop and takes the instance downCVE-2025-10903 · GitLab EE (SCIM user provisioning)Medium
- rpc.mountd: NFSv3 client bypasses export restrictions and root_squash on subdirectoriesCVE-2025-12801 · nfs-utils rpc.mountd (NFSv3 export subtree access)Medium
- OpenVINO Model Server: An unauthenticated request can drive OpenVINO Model Server into unbounded resource consumptionCVE-2025-22892 · OpenVINO Model ServerMedium
- IBM Storage Scale SMB protocol stack (inherited ACL handling): Files created or modified over SMB inherit permissionsCVE-2025-36104 · IBM Storage Scale SMB protocol stack (inherited ACL handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.