TIBCO Messaging - Apache Kafka Distribution - Schema Repository Vulnerable to CSRF Attacks
Original release date: November 6, 2018 Last revised: Source: TIBCO Software Inc.
Description
The component listed above contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks.
Impact
The impact of this vulnerability includes the theoretical possibility that an attacker could gain full access to the configuration of message schemas used with an Apache Kafka deployment. With such access, the attacker could also configure Apache Kafka communications to fail.
CVSS v3 Base Score: 7.5 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Issue/Introduction
Security Advisory regarding TIBCO Messaging - Apache Kafka Distribution
Environment
Systems Affected
TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community
Edition version 1.0.0
TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise
Edition version 1.0.0
The following components are affected:
* Schema repository server (tibschemad)
Resolution
Solution
TIBCO has released updated versions of the affected components which address these issues.
For each affected system, update to the corresponding software versions:
TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition version 1.0.0 update to version 1.0.1 or higher
TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition version 1.0.0 update to version 1.0.1 or higher