Vulnerabilities (CVE)

Filtered by vendor Vmware
Filtered by product Spring For Apache Kafka
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34040 1 Vmware 1 Spring For Apache Kafka 2024-11-21 N/A 5.3 MEDIUM
In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explici ...

Show More