# Security Advisory: CVE-2023-25194 Kafka Connect

[Blog](/blog/)&gt;[Technology](/blog/category/technical/)&gt;Security Advisory: CVE-2023-25194 Kafka Connect 

Security Advisory: CVE-2023-25194 Kafka Connect
===============================================

February 23, 2023 | By [ Instaclustr ](https://www.instaclustr.com/blog/author/instaclustr/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=Security%20Advisory:%20CVE-2023-25194%20Kafka%20Connect&url=https://www.instaclustr.com/blog/security-advisory-cve-2023-25194-kafka-connect/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/security-advisory-cve-2023-25194-kafka-connect/&title=&summary=Security%20Advisory:%20CVE-2023-25194%20Kafka%20Connect&source=) 

The Apache Kafka® project [announced](https://kafka.apache.org/cve-list) on February 8, 2023, that a security vulnerability had been identified in Kafka® Connect, CVE-2023-25194.

This vulnerability is related to the Kafka Connect worker and has been there since version 2.3.0. Using an arbitrary Kafka client SASL JASS config and an SASL-based security protocol, it is possible to create or modify connectors on a Kafka Connect worker. When exploited this vulnerability allows the attacker to connect to an arbitrary LDAP server and deserialize the LDAP response, which the attacker can use to execute Java deserialization gadget chains on the Kafka Connect Server. This can result in unrestricted deserialization of untrusted data.

The CVE report recommends that users of Kafka Connect validate connector configurations and only allow trusted JNDI configurations.

**Mitigation:**

When we received the advisory we investigated the vulnerability and its potential impact on customers of our Instaclustr for Kafka Connect service. Results of our analysis are as follows:

- Instaclustr’s service does not support Kafka Connect connectors using the authentication methods mentioned in this vulnerability.
- We do not enable egress firewall rules to connect to any arbitrary JNDI/LDAP service.

Based on this, we do not believe our Managed Service customers need to take any action to mitigate this vulnerability.

For support-only customers we recommend:

- Validating connector configurations to only allow trusted JNDI configurations
- Verifying any connector dependencies for vulnerable versions, updating connector dependencies, and removing vulnerable connectors
- Upgrading to version 3.4.0 and leveraging the **org.apache.kafka.disallowed.login.modules** system property to disallow the vulnerable login module.

If you have any further queries regarding this vulnerability and its relation to Instaclustr services, feel free to contact us at <support@instaclustr.com>.

 

 [ Add Instaclustr as a preferred source on Google ](https://google.com/preferences/source?q=instaclustr.com)



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
